TOPdesk typical implementation process:
Project Kick-off and Requirement Gathering: The process begins with a project initiation meeting to define objectives, scope, key stakeholders, and deliverables, ensuring alignment with organizational goals and ITIL best practices.
Planning and Design: A detailed implementation plan is created, covering process selection (such as incident, request, change management), resource allocation, milestones, and risk mitigation strategies. This phase includes mapping desired workflows and integrations with existing systems.
System Configuration and Customization: TOPdesk consultants help configure the software environment, set up user roles, permissions, and tailor workflows, forms, and automation rules to fit organizational needs. Code-free designers allow for easy customization without programming skills.
Data Migration: Existing data, such as tickets, assets, and user information, is migrated into TOPdesk, ensuring continuity and historical record-keeping.
Training: A “train the trainer” approach is used, where key users and administrators receive in-depth training, which they then cascade to other staff. Training can be delivered onsite or remotely and is supported by manuals, guides, webinars, and videos.
Testing and Validation: The configured system is tested with real scenarios to ensure all processes work as intended. Feedback is collected and adjustments are made as needed before going live.
Go-Live: The platform is launched for end users, often in phases (e.g., starting with incident management, then adding change management and self-service portal), to ensure a smooth transition and minimize disruption.
Post-Go-Live Support: Ongoing support is provided through a dedicated channel, knowledge base, and consultant check-ins to resolve issues, answer questions, and ensure adoption.
Continuous Improvement: After implementation, regular reviews and maturity assessments are conducted to identify areas for optimization and further alignment with best practices.
TOPdesk is highly customizable, enabling organizations to adapt the platform to their specific business needs across a wide range of areas. Below are key data points demonstrating the breadth and depth of customization options available:
1. User Interface and Personal Settings
Operators can customize their personal settings, including overview display options, accessibility features (such as high-contrast color schemes), language preferences, and more.
The homepage/dashboard can be tailored by adding, removing, or rearranging widgets, shortcuts, and reports to provide quick access to frequently used features and data.
The quick launch bar and workspace layout are configurable, allowing users to streamline navigation based on their roles and preferences.
2. Process and Workflow Customization
Organizations can create custom templates, forms, workflows, and routing options using code-free designers, making it possible to mirror unique business processes without programming knowledge.
Workflow automation is supported through events and actions, enabling the automation of repetitive tasks, notifications, and approvals across modules such as Incident, Change, and Asset Management.
Permission controls are highly granular, allowing administrators to tailor access at the person/group, categorization, and location levels.
3. Self-Service Portal and Branding
The Self-Service Portal is fully configurable: organizations can add custom tiles, adjust colors, branding, and terminology, and set visibility controls to create a user-specific service catalogue.
Email notifications and templates can be customized to match the organization’s branding, including editing HTML for colors, layout, and content.
4. Reporting and Dashboards
Dashboards are completely customizable, allowing users to create and organize reports, KPIs, and selections with drag-and-drop widgets.
The reporting engine supports the creation of custom reports using all available data fields, and integrates with business intelligence tools like Power BI and OData for advanced analytics.
5. Integration and API Access
TOPdesk offers a robust API, enabling integration with third-party systems for data exchange, process automation, and custom widget development.
API documentation and sandbox environments are available to facilitate custom integrations and extensions.
6. Modular and Scalable Design
The platform’s modular architecture allows organizations to start with basic configurations and expand functionality as needs evolve, supporting both small teams and large enterprises.
An unlimited number of custom alerts, categorizations, statuses, and additional fields can be created for each functional module.
7. Additional Customization Features
Customizable fields, forms, templates, and reports are available across modules, supporting unique data capture and process requirements.
Operators can build, customize, and schedule reports, and add up to 60 additional fields within two tabs for each module card.
TOPdesk’s pricing model is transparent and primarily based on the number of agents (users who handle tickets), with three main subscription tiers: Essential ($76/agent/month), Engaged ($109/agent/month), and Excellent ($155/agent/month)14. While the base subscription includes unlimited assets, tickets, end users, and core features, there are additional costs to consider depending on your organization’s needs.
Software access (SaaS or on-premises)
Hosting and updates: Bi-weekly software updates for SaaS are free.
Local support: Product-related support is included in all plans.
Unlimited end users and assets: No extra charge for these.
Self-Service Portal, Knowledge Base, and Reporting: Included in all plans.
1. Setup and Implementation Fees
Implementation by consultants is not included in the subscription and comes at a surcharge. The cost depends on the complexity and scope of your setup.
Data migration from legacy systems may incur extra fees, depending on the volume and complexity of the data.
Staff training, if needed, is an additional cost and can range from a few hundred to several thousand dollars per employee, depending on the level required.
2. Customization and Integration
Custom development or advanced customizations may require technical assistance and can be expensive, especially for complex needs. Costs can range from a few thousand to several hundred thousand dollars for significant projects.
Integrations with other tools (beyond standard integrations and open API) may be charged separately, depending on the nature and depth of integration.
3. Additional Modules and Features
Modular pricing: You only pay for the modules you need, but adding extra modules (like Reservations Management or advanced reporting) increases the total cost.
Consultancy days or additional services: These are available for a fee if you require expert assistance beyond standard support.
4. Data Overages
If your usage exceeds the limits set in TOPdesk’s fair use policy, you may incur extra charges for additional data storage or usage.
Ongoing maintenance (software updates, bug fixes, and standard support) is included in the subscription—no separate maintenance fees.
Standard support is included in all plans. The Excellent plan offers enhanced support features such as 24/5 support and annual health checks.
TOPdesk provides a suite of training and support services to ensure new users can effectively adopt and utilize the platform. These services are tailored to different user roles and organizational needs, ranging from standard onboarding to advanced, customizable training and ongoing support.
Standard Training Courses
Practical, hands-on sessions for groups (up to 10 users) led by a consultant.
Training begins with a live demonstration using the organization's own TOPdesk environment, followed by exercises and direct implementation of learned skills.
Core agent training is the foundation for independent work with TOPdesk.
Role-Specific Training
Application managers (administrators) are involved early in the implementation and receive targeted training, usually only needed again if there is staff turnover. This typically takes between half a day and a full day.
Specialized training is available for individual modules (e.g., change management) and technical topics such as API usage and automation.
Onboarding and Train-the-Trainer Approach
Implementation is guided by consultants using a train-the-trainer model, enabling organizations to build in-house expertise and self-sufficiency.
Training is mapped to the customer’s specific processes and requirements, with consultants providing presentations, workshops, and one-on-one sessions as needed.
Flexible and Customizable Training
Training content can be customized for individuals or corporate groups to match specific project requirements and industry needs.
Delivery modes include online instructor-led sessions, in-person classroom training, and self-paced learning options.
Crash courses and flexible scheduling are available to accommodate different learning needs and timelines.
Ongoing Learning Resources
Access to manuals, guides, webinars, blogs, and training videos is provided for continuous learning and reference.
Update training keeps users informed about new features and changes in the platform.
A comprehensive, searchable online knowledge base is available for self-service support, covering common questions and troubleshooting steps.
Direct Support Channels
Users can submit tickets, contact support agents via phone or email, or request remote support for more complex issues.
Support is provided by technical specialists with deep knowledge of the platform, ensuring prompt and effective assistance.
Consultancy and Additional Support
Consultancy is available both onsite and remotely for advanced configuration, optimization, and process mapping.
Enhanced support options can be arranged for organizations with more complex needs.
Onboarding Support
Dedicated teams guide new customers through the onboarding process, including planning, implementation, and initial training.
TOPdesk implements a comprehensive set of security measures to safeguard customer data, addressing both regulatory compliance and technical best practices. Here are the key data points on how TOPdesk protects data:
1. Certifications and Compliance
TOPdesk is SOC 2 certified, and all data centers hosting the service are ISO 27001 accredited, meeting international standards for information security management.
The platform is designed to support GDPR compliance, with features and procedures aligned to the requirements for data protection, retention, and incident response.
2. Data Retention, Anonymization, and Deletion
Built-in anonymization features allow organizations to set custom periods for anonymizing or deleting personal data from user and operator records after they leave the organization.
The system can automatically delete content from closed cards and attachments after a user-defined period, minimizing the risk of retaining unnecessary personal data.
SaaS customers benefit from automated backup retention policies that comply with GDPR, while on-premises customers are advised to manage backup retention in line with best practices.
3. Access Controls and Authentication
Multi-factor authentication (2FA) is supported, as well as identity federation with providers like Google Apps and Single Sign-On (SSO) integration.
Access to TOPdesk is restricted to authorized users, with granular permission controls managed through personal network accounts and Active Directory groups.
Extensive permission groups and filters ensure users only see the information they are authorized to access.
4. Data Center and Infrastructure Security
Customer environments are isolated from each other to ensure data segregation and optimal resource allocation.
Data centers are managed by third parties and meet Tier 3 standards, with constant surveillance and redundant infrastructure for high availability and resilience.
Customer files are stored on encrypted disks; while databases are not yet encrypted, data is fragmented and distributed across multiple drives for added protection.
5. Monitoring, Incident Response, and Penetration Testing
24/7 monitoring systems track health metrics, availability, and potential threats across all environments.
Daily penetration tests and regular external audits are conducted, with incidents treated as high priority and communicated to affected customers rapidly (within 15 minutes of detection).
Security incident procedures are in place to inform customers (the Controller) of breaches, in line with GDPR requirements.
6. Security Governance and Employee Training
Information security is governed by a named board-level executive and follows frameworks such as COBIT.
Employees undergo regular security awareness training and must pass background checks before accessing SaaS systems.
Policies and procedures are reviewed biannually, and all staff are trained on security responsibilities and data handling.
7. Customer Control and Data Portability
Customers can extract their data at the end of a contract at no extra cost, with data automatically deleted 30 days after contract termination.
Data sanitization processes ensure deleted data cannot be directly accessed, and equipment disposal follows strict in-house destruction protocols.
8. Additional Security Features
Automated failover, redundant power, and load balancing ensure high availability (99.7% uptime guarantee)
Update Frequency for SaaS
TOPdesk SaaS environments receive new and updated features continuously, following a continuous deployment model. This means updates are rolled out as soon as they are ready, ensuring customers always have access to the latest features, improvements, and security patches.
Security issues are addressed with high priority and are resolved as quickly as possible.
Update Management for SaaS
Updates are first deployed in test environments, then to TOPdesk’s own production environment, and finally to customer SaaS production environments.
Customers can stay informed about new features and changes via the Product Update newsletter and Release Notes, which are accessible from within the platform.
SaaS customers do not need to manage the update process themselves; updates are applied automatically by TOPdesk.
Update Process for On-Premises/Virtual Appliance
On-premises and Virtual Appliance customers must manually download and install updates.
The update process involves stopping TOPdesk, backing up the database and configuration files, applying the update, and then restarting the system.
Updates can typically be completed within a half day, but it is recommended to perform them outside working hours to minimize disruption.
Customer-specific solutions or add-ons may need to be rebuilt or reinstalled after an update.
Release documentation and update instructions are provided to guide administrators through the process.
General Notes
Customers can request an acceptance (test) environment to preview updates before they are applied to production.
Customer as Data Controller: In the context of TOPdesk, your organization (the customer) is considered the Data Controller. This means you determine the purpose and means of processing personal data within TOPdesk. You are responsible for defining what data is registered, how it is used, and how long it is retained.
TOPdesk as Data Processor: TOPdesk acts as the Data Processor, providing the platform and ensuring that it operates securely and in compliance with relevant regulations (such as GDPR). TOPdesk follows the instructions of the Data Controller regarding data handling, retention, and deletion.
Control Over Data: Your organization retains full control over the data entered into TOPdesk. You set access permissions, retention periods, and anonymization or deletion procedures for personal data and attachments.
Data Extraction: Customers have the right and ability to extract their data from TOPdesk at the end of the contract or as needed. TOPdesk provides mechanisms for exporting data, ensuring you can retrieve your information in a usable format.
End-of-Contract Data Handling: After contract termination, data is automatically deleted from TOPdesk systems after a defined period (e.g., 30 days). During this period, customers can request and receive their data at no extra cost.
Anonymization and Deletion: The platform includes features to anonymize or delete personal data and attachments based on custom retention policies, supporting compliance with data protection regulations and facilitating data minimization.
GDPR Alignment: TOPdesk’s policies and features are designed to support GDPR compliance, including data subject rights, retention limits, and secure deletion.
TOPdesk is designed with scalability and flexibility in mind, allowing organizations to adjust their subscription and feature set as their needs change. Here’s how TOPdesk handles scaling up or down:
1. Flexible, Modular Licensing
TOPdesk uses a modular structure, enabling you to add or remove features, add-ons, and integrations as your requirements evolve.
You only pay for the modules and number of agents (users who handle tickets) you need, and you can increase or decrease these at any time.
End users (those who only view dashboards or submit requests) are unlimited and free; only agents incur charges.
2. Adjusting Agent Numbers
The pricing model is based on the number of agents, with a regressive pricing structure—the price per agent decreases as you add more agents.
You can scale up by adding agents as your organization grows, or scale down by reducing agent numbers if your needs decrease.
Changes to your plan can be made at any time by contacting TOPdesk, ensuring your subscription matches your current organizational size and needs.
3. Adding or Removing Features
Features, add-ons, and integrations can be added or removed from your plan as needed, such as Reservations Management or consultancy days.
The system’s modularity ensures you don’t pay for unnecessary features and can quickly adapt to new business requirements.
4. No Hidden Costs
TOPdesk emphasizes transparent pricing, with no hidden fees for scaling up or down.
Unlimited assets and end users are included in all plans, so scaling in terms of service coverage does not incur extra charges.
5. Support for Large and Small Organizations
The platform is suitable for mid-size to large organizations, but its flexible licensing and modular design make it equally appropriate for smaller businesses planning to grow.
6. Simple Process for Changes
Automatic Renewal: TOPdesk contracts typically include an initial term (such as one year) and will automatically renew for additional periods (often of the same length) unless a party provides written notice of non-renewal within a specified timeframe before the end of the current term.
Notice Period: The standard notice period to prevent auto-renewal is usually at least 30 days before the renewal date, but this may vary depending on the specific contract15. Failing to provide notice means the contract renews under the same terms and conditions.
Renewal Terms: Unless otherwise agreed, renewal is generally on the same terms as the original agreement. Any changes to pricing or terms must be communicated and agreed upon before renewal.
Opportunity for Review: Customers should review their contract and notify TOPdesk in writing if they do not wish to renew, allowing them to renegotiate or terminate as needed before the renewal date.
Termination for Cause: Customers may terminate the agreement immediately if TOPdesk fails to meet contractual obligations, such as not correcting significant defects after notification. In such cases, customers may be entitled to a refund of paid license fees for the undelivered or unaccepted phase.
Standard Cancellation: To cancel without cause, customers typically must provide written notice within the notice period (commonly 30 days before renewal)15. If notice is not given in time, the contract auto-renews, and cancellation may only take effect at the end of the next term.
Cooling-off Period: For contracts arranged online or remotely, there may be a statutory 14-day cooling-off period during which customers can cancel for any reason and receive a full refund, unless services have already been provided at their request. This is subject to local consumer protection laws and may not apply to all business contracts.
Consultancy and Additional Services: Cancellation of booked consultancy services requires at least five business days’ notice. Cancelling with less notice may incur a fee (50% of the consultancy fee if cancelled within five days, or 100% if cancelled within 24 hours).
TOPdesk meets several recognized compliance standards and frameworks, ensuring robust information security, data protection, and accessibility for its users. Here are the key compliance standards and certifications TOPdesk adheres to:
Scope: The cloud-hosted TOPdesk service is fully covered by ISO/IEC 27001 certification, accredited by EY CertifyPoint as of February 2024.
Coverage: This standard ensures that TOPdesk’s information security management system (ISMS) meets international best practices for protecting data confidentiality, integrity, and availability.
Note: The certification applies to the cloud service and associated data centers, not to the TOPdesk software itself when deployed on-premises.
Scope: TOPdesk is SOC 2 certified, demonstrating adherence to strict criteria for managing customer data based on the five "trust service principles": security, availability, processing integrity, confidentiality, and privacy.
Scope: TOPdesk holds the UK government's Cyber Essentials certification, which covers essential technical controls to guard against common cyber threats.
Scope: TOPdesk is designed to support organizations’ compliance with the EU’s GDPR. The platform provides features such as data anonymization, customizable data retention, and deletion tools to help customers fulfill GDPR obligations.
Responsibilities: While TOPdesk acts as the data processor, the customer remains the data controller and is responsible for defining and implementing their own data protection policies within the system.
Scope: TOPdesk supports organizations in meeting the requirements of the EU’s NIS 2 Directive for cybersecurity and incident management. The platform enables structured management of security incidents, risk monitoring, and compliance tracking for NIS .
Scope: TOPdesk is actively working towards achieving WCAG 2.2 Level AA compliance to enhance accessibility for users with disabilities. Accessibility is integrated into the product’s development and quality assurance processes.
