Complete guide for coordinators, custodians, contributors, reviewers, and privacy analysts using AccessPoint

Last updated: August 06, 2026 by Steve

User Guide

The User Guide covers everything you do inside AccessPoint — from logging an access request to running a privacy assessment, handling an incident, or building a report. Jump to the area you work in below. Each page matches a screen you can open the in-app Help (?) button from.

Privacy note: Custodians and contributors always work from sanitized instructions and never see requestor personal information. Only coordinators, reviewers, and privacy staff see requestor identity.

Start here

Dashboards & views

  • My Day — the prioritized personal feed and pinned report tiles (the default landing tab)
  • Requests dashboard — searching, filtering, sorting, and managing the request list
  • Assignments dashboard — a custodian's assigned work across requests and assessments
  • Tasks dashboard — a contributor's task assignments, uploads, and completion
  • Reviews dashboard — reviewing submissions, approving, or requesting changes
  • Dashboard views — saving and switching between column, filter, and sort configurations
  • Assessments dashboard — the PIA/AIA register list, stat cards, and starting a new assessment
  • Incidents dashboard — the breach register, stat cards, and reporting a new incident
  • Complaints dashboard — complaints and appeals with their statutory clocks, and registering from email
  • Risks dashboard — the standalone risk register view and the risk portfolio analysis card

Access requests

  • Creating requests — request type, requestor picker, and intake details
  • Request overview — status, key dates, scope, extensions, and the lifecycle rail
  • Requestor — requestor contact, communication preferences, and correspondence history
  • Assignments — creating custodian assignments, instructions, and collection progress
  • Documents — the review workspace: upload, tags, families, read tracking, and redaction
  • Collaboration — advisors, readers, consultations, and internal comments
  • Response & fees — the next-step card, fees, response method, closure with its completeness check, and the case audit export
  • Activity — the audit trail of changes, status transitions, and user actions

Documents & redaction

  • Documents workspace — upload, tag, triage, redact, and package records with exemptions
  • Duplicate documents — decision-based duplicate handling with an authoritative copy and redaction propagation

Assignments, tasks & delegation

  • Assignment details — instructions, tasks, documents, attestation, and approve/request-changes
  • Task details — instructions, repository outcomes, documents, hours, and submit
  • Repository details — a records source, its search outcomes, and task association
  • Delegations — arranging a colleague to cover your work while you're away (an access overlay, not a reassignment)

Requestors & contacts

  • Requestors & contacts — the contacts workspace: requestors, institutions, intake queue, and consultation contacts
  • Requestor contact — identity, language, fee category, flow control, the Conduct (F&V) workspace, and merge
  • Requestor institution — organization identity, affiliated contacts, active-request caps, and merge

Consultations & correspondence

  • Consultations — consultation parties, statutory windows, correspondence, and outcome
  • Correspondence — a logged or generated communication with the requestor and its thread
  • Sending correspondence — the template library, merge fields, and send/capture with the PII firewall

Privacy assessments & ROPA

  • Creating assessments — starting a PIA/AIA/Security assessment with a type, template, and screener
  • Assessment details — sections filler, section assignments, risks, documents, review, and closure
  • Section assignments — assigning a questionnaire section to a collaborator and merging their draft
  • Privacy subjects & controls — the directory of reusable privacy subjects (programs, systems, and more), their Art.30 ROPA records, linked controls, and the vendor register
  • Privacy subject details — identity, records of processing, and assessment/incident history

Incidents & breaches

  • Creating incidents — logging a privacy incident or breach record
  • Incident details — facts, containment, risk of harm, notifications, remediation, and closure
  • Incident measures — a containment or remediation measure, its type, effectiveness, and progress

Complaints & appeals

  • Creating complaints — registering a complaint or appeal record
  • Complaint details — parties, statutory clocks, allegations and findings, correspondence, investigation, and closure
  • Complaint workstreams — a delegated line of investigation: findings work product and the submit → review lifecycle

Risks & commitments

  • Risk details — risk rating, management cards, treatment plan, KRI monitoring, and closure
  • Risk treatment tasks — a mitigation action on a risk's treatment plan
  • Risk indicators — key risk indicators (KRIs): thresholds, readings, and monitoring cadence
  • Commitments — a tracked promise or measure with cadence and check-ins

AI Assist

Reports & analytics

  • Reports — the report period selector and grouped menu of fixed reports
  • Case hygiene — open QA findings across every open case, from the same deterministic rules as the per-case Case check card
  • AI systems register — deployment, risk class, human involvement, and derived approval position of ADM-flagged privacy subjects
  • Custom reports & Report Studio — dashboards of report widgets: subject, groupings, measures, filters, and export
  • Retention review — records past their retention period across all five registers, and the purge workflow

Notifications