Configuration and administration guide for AccessPoint system administrators

Last updated: August 06, 2026 by Steve

Administrator Guide

This guide covers AccessPoint deployment, configuration, and ongoing administration. Almost nothing is hard-coded — AccessPoint follows a configuration-over-code approach, so you can reshape request types, letters, exemptions, calendars, roles, and the privacy program from Settings without a developer or a redeployment.

Start here: Deployment Guide — provision Azure resources, install the SPFx web part and Teams app, and connect them to your Microsoft 365 tenant.

Who is this guide for?

  • IT Administrators responsible for deploying and maintaining AccessPoint
  • SharePoint and Azure Administrators who manage the Microsoft 365 and Azure environment
  • System Owners who configure business rules and operational settings

Admin Settings panel

The pages below mirror the Settings hub. See the Settings Overview for the hub as the app presents it.

Getting started

  • Settings — the grouped directory of every configuration area
  • Setup — API base URL, Azure deploy/update, and email + Teams notifications
  • Jurisdiction packs — import jurisdiction or universal packs and review applied packs
  • Organization — the institution display name merged into notices, letters, and tokens
  • Languages — active tenant languages, default language, and display order
  • Calendars — business-day calendars and statutory holidays for due-date math
  • Features — per-tenant feature opt-out toggles
  • AI suggestions — the guidance-proposal inbox for AI-drafted playbook and catalog refinements, plus question mining of Ask AccessPoint questions into aggregate themes
  • Data import & export — migrate historical caseloads via a tenant-generated import template, and export a business-readable Excel workbook

Users, roles & access

  • Manage users — assign or remove application roles per user (last-admin guard)
  • Roles & permissions — build tenant roles from a categorized, scoped permission catalog

Request intake

Request lifecycle

  • Extension reasons — reasons with suggested/min/max durations and applicable request types
  • Closure reasons — the reasons a request can be closed
  • Response methods — how responses are delivered to requestors
  • SLA targets — per-stage business-day targets for requests, assignments, and consultations

Collaboration & reviews

Documents & review

Privacy configuration

  • Assessment types — PIA/AIA/Security types, scoring, tiering, and summary templates
  • Assessment statuses — configurable status labels for the assessment lifecycle
  • Assessment templates — the questionnaire builder (sections/questions), versioning, and screeners
  • Control option lists — the Controls-library lookups: control families, control kinds, and baseline profiles
  • Incident types — categories for privacy incidents and breaches
  • Incident statuses — configurable status labels for the incident lifecycle
  • Incident option lists — cause, PI-category, harm, containment, remediation, and notification taxonomies
  • Complaint types — categories for complaints and appeals
  • Complaint statuses — configurable status labels for the complaint lifecycle
  • Risk categories — shared risk-register categories and appetite settings
  • Privacy subject choice fields — subject types (with the AI/ADM system flag), categories of personal data (shared with incident reporting), categories of data subjects, and categories of recipients

Reporting configuration

System & compliance

  • Audit ledger — the append-only, hash-chained audit trail and integrity verification
  • Disaster recovery — backup, recovery, rollback procedures, health monitoring, and scaling