The whole access and privacy mandate, running in your Microsoft 365 tenant

Not a template library — an operating platform. AccessPoint runs ATIP and FOI requests, privacy and algorithmic impact assessments, breach response, complaints, and your privacy risk register where the work actually happens: statutory deadlines computed from your legislation, every action written to a hash-chained audit ledger, and your data never leaving your control.

AccessPoint access and privacy dashboard running in SharePoint

AccessPoint began as an access-to-information request manager and grew into the integrated operating platform for a public-sector access and privacy office. It isn't a suite of separate tools bolted together: every module is configuration-driven and runs on one shared foundation — the same identity, hash-chained audit ledger, review engine, and reporting — so there's a single system to learn, govern, and report on, with no per-user fees.

One Platform, the Whole Mandate

Access requests, privacy assessments, breach response, complaints, and risk — every module sharing one identity, one audit ledger, and one reporting spine.

Access to information requests

The original strength: intake to response for ATIP, FOI, and GDPR requests, built on Microsoft 365 — with a browser-native redaction studio at its core.

Redaction & Exemptions

A full redaction studio in the browser — no desktop tools required. Select text to sever, find-and-redact every occurrence at once, keep live patterns running on newly arriving documents, and import redactions from an earlier request that already processed the same document. Every mark carries its statutory exemption — primary and fall-backs — and the disclosure package ships with a defensible exemption manifest.

Redaction & Exemptions Click to enlarge

Integrated with Microsoft 365

Search SharePoint, OneDrive, and Outlook and add records straight to a request — and capture Teams chats, OneNote pages, calendars, and even Copilot interaction history the same way. An email in your intake mailbox becomes a fully-formed request in one step, with the message attached as its first document.

Integrated with Microsoft 365 Click to enlarge

Deadline & Extension Management

Automatic due-date calculation on statutory business-day calendars, with clock pauses, holds, and extension tracking. When a due date passes unanswered, the statutory consequence — deemed refusal — is recorded automatically, and a built-in abandonment workflow handles requestors who stop responding.

Deadline & Extension Management Click to enlarge

Document Collection & Review

Assign collection tasks to custodians, classify records by relevance, tag and de-duplicate with per-copy decisions that stand up to review, and track read-through — all in a single faceted workspace with full-text search that reads even scanned paper records (optional OCR).

Document Collection & Review Click to enlarge

Digital Attestations

Custodians certify their searches and production with legally-defensible digital attestations, captured against the record and backed by the audit ledger.

Digital Attestations Click to enlarge

Frivolous & Vexatious, Defensibly

When a requestor's conduct becomes the issue, build the record that survives a commissioner's challenge: computed conduct signals from their own filing history, a balanced analysis memo, an append-only conduct log, and a formal determination with its legal basis — evidence first, determination last.

Frivolous & Vexatious, Defensibly Click to enlarge

AI Assist

Optional AI that runs on Azure OpenAI in your own tenant — Microsoft never trains on your data, nothing is stored, and a person always decides. Every feature is individually switchable.

AI Redaction Analysis

Beyond pattern rules, the AI reads documents in context and proposes redactions for personal, advice, privileged, and commercial content — each with a confidence score and reason — into the same human review pipeline as every other suggestion.

AI Redaction Analysis Click to enlarge

AI Intake Triage

An AI triage card reads the intake text on a request, incident, or complaint and suggests a title, a plain summary, key topics, a ready-to-append scope, third parties whose interests may need consulting, and clarification questions worth asking — every suggestion is one click to apply, and nothing is applied automatically.

AI Intake Triage Click to enlarge

Ask AccessPoint

A read-only assistant answers questions about the case in front of you — "what's outstanding before I can close?" — with clickable citations back to the record and statute-aware answers that cite the governing legislation, never invented section numbers. A My caseload mode answers across your own open work, and it never changes anything.

Ask AccessPoint Click to enlarge

Ask AccessPoint for Reporting

Ask a reporting question in plain language and get a report built against the same field catalog as the Report Builder — it never writes SQL, personal-data fields are never offered to it, and every result opens in the builder to refine. A wrong answer is a wrong chart, never a data leak.

Ask AccessPoint for Reporting Click to enlarge

AI-Assisted Drafting

A Draft with AI button appears wherever a narrative is written — requestor letters, breach-notification rationales, assessment summaries, and custodian search instructions drafted from the request's own scope, behind the PII firewall by construction. Drafts are grounded strictly on the record's facts; anything unverifiable is flagged [VERIFY] rather than invented, and lands in the editor for a person to review, edit, and save.

AI-Assisted Drafting Click to enlarge

Assessment Answer Suggestions

In a PIA or AIA, AccessPoint drafts grounded answers for a section's unanswered questions from the assessment's own documents, its record, and your organization profile — with an "insufficient information" hint instead of filler, accepted or dismissed per question, plus a consistency check across the whole set.

Assessment Answer Suggestions Click to enlarge

Responsible by Design

AI Assist is optional and runs on Azure OpenAI in your own Azure tenant: Microsoft never trains on your data, prompts and responses are never stored, a person always decides, and a monthly token budget you control caps the spend. Each feature is individually switchable, you choose where inference is processed (globally or bounded to the EU/US data zone), and every case's activity feed discloses the AI calls made on it.

Responsible by Design Click to enlarge

Privacy & AI impact assessments

Operate PIAs and Algorithmic Impact Assessments end to end — screen, assess, score, review, publish, then monitor the commitments and risks that come out of them.

Privacy Impact Assessments (PIA)

Run PIAs, not just fill them in. A configurable questionnaire engine with preliminary screeners, typed questions, an embedded risk register, and a regulator-ready summary export — configured to the assessment mandate that applies to your organization.

Privacy Impact Assessments (PIA) Click to enlarge

Algorithmic Impact Assessments (AIA)

Assess automated decision-making systems against the directive or policy that applies to you — a public-sector AI directive, your own responsible-AI framework, or both. The same engine that runs your PIAs runs your AIAs — scored, tiered, reviewed, and published with an auditable trail.

Algorithmic Impact Assessments (AIA) Click to enlarge

Screeners & Section Assignment

A preliminary screener decides whether a full assessment is even needed. When it is, hand individual sections to subject-matter experts who fill in only their part — answers autosave, and the coordinator merges on approval. No expert ever sees the whole file.

Screeners & Section Assignment Click to enlarge

Records of Processing (ROPA)

Every assessment attaches to a durable privacy subject — a reusable program or system carrying its GDPR Article 30 record: lawful basis, data-subject and recipient categories, retention, safeguards, and cross-border transfers. Export the full ROPA register on demand, with a vendor register beside it tracking every processor's DPA status, review cadence, and risk level.

Records of Processing (ROPA) Click to enlarge

Breach & incident management

From discovery to statutory notification, with obligations computed for you.

Incident & Breach Intake

Log a privacy breach in seconds, then work it to closure: cause and circumstances, affected individuals, categories of personal information, containment measures, and a confirmed-contained shield with date and signatory.

Incident & Breach Intake Click to enlarge

Live Breach-Notification Calculator

A real-risk-of-significant-harm evaluation drives a live obligations checklist: who must be told, by when, and what each notice must contain, computed from the incident's legal authority. Mark notices sent, dismiss with a recorded rationale, or generate the letter.

Live Breach-Notification Calculator Click to enlarge

Containment & Remediation

Track corrective and preventive actions as assignable measures with owners, target dates, effectiveness ratings, and a running progress log. Measures are a permanent part of the incident record.

Containment & Remediation Click to enlarge

Complaints & appeals

Track Commissioner complaints and appeals with their own statutory clocks and investigation workspace.

Complaints & Appeals

Track external challenges from a Commissioner, an appeal of a decision, or a complaint made directly to your institution — one kind-aware intake handles them all, each with its own statutory clocks, admissibility check, and grounds catalogue. Break a complaint into allegations, record per-allegation findings, and track the regulator's recommendations as commitments through to completion.

Complaints & Appeals Click to enlarge

Investigation & Representations

Delegate evidence-gathering as sanitized workstreams, run the institution's representation through a configurable sign-off, and send acknowledgement and response letters from a two-lane correspondence desk that stamps the statutory clocks automatically. Close with a guided disposition covering findings, judicial review, and order compliance.

Investigation & Representations Click to enlarge

Privacy risk register & commitments

An ISO 31000 register that turns assessment findings into monitored, governed action.

Privacy Risk Register

An ISO 31000 register with inherent and residual scoring, treatment strategies, and governed risk acceptance — over-appetite sign-offs require a justification and an expiry date. Risks surface from assessments and incidents and roll up across your whole program.

Privacy Risk Register Click to enlarge

Key Risk Indicators & Commitments

Monitor risks with Key Risk Indicators — thresholds, RAG status, and a readings history — and track the privacy commitments that come out of an assessment to completion, with recurring check-ins so nothing is forgotten.

Key Risk Indicators & Commitments Click to enlarge

One governed platform

The shared spine every module runs on — configure it once, reuse it everywhere.

Migrate In, Export Out

Leaving a legacy system shouldn't take an ETL project. A guided, validated Excel workbook brings your history across — in-progress cases included, statuses and due dates intact, so there's no cutover. And the same panel exports everything back out in one click, so you're never locked in.

Migrate In, Export Out Click to enlarge

Review & Approval Workflows

One configurable review engine — sequential or parallel stages, gating, and reminders — approves redactions, sign-off on an assessment, representations on a complaint, and more. Configure it once; reuse it everywhere.

Review & Approval Workflows Click to enlarge

Hash-Chained Audit Ledger

Every action across every module is written to an append-only, hash-chained ledger with integrity verification — and exported as court-ready case audit exports. Nothing is edited away; the record proves itself.

Hash-Chained Audit Ledger Click to enlarge

Reporting & Report Studio

Statutory annual-report templates, fixed operational reports, and SLA and workload dashboards — plus Report Studio, where you compose report widgets into your own dashboards with one shared period and pin them to My Day as live tiles. No SQL required.

Reporting & Report Studio Click to enlarge

Role-Based Dashboards & My Day

Every role gets a purpose-built view — coordinators see the whole picture, custodians see only their assignments — and a computed My Day list tells each person exactly what needs attention next. Cover a vacancy or vacation by delegating a whole caseload in one step, and take it back just as cleanly.

Role-Based Dashboards & My Day Click to enlarge

Consultations & Correspondence

Run inter-departmental and third-party consultations with their own statutory windows, and compose templated correspondence from merge fields that passes through a PII firewall so the right people see the right details.

Consultations & Correspondence Click to enlarge

Native to Microsoft 365

Your tenant, your data, your compliance — with no new infrastructure to run.

Data Sovereignty

Requests, documents, assessments, incidents, and audit history stay in your Microsoft 365 and Azure tenant and never leave your control. No third-party cloud, no cross-border transfers, no vendor access to your data.

Data Sovereignty Click to enlarge

Enterprise Security

Authentication through your existing Microsoft Entra ID — no new passwords. Granular, tenant-configurable permission roles enforced server-side, a PII filter that walls custodians and contributors off from requestor identity, TLS 1.3, and Entra-only database authentication — no SQL credentials ever exist.

Enterprise Security Click to enlarge

Deployed in Minutes

Deploy the Azure backend from a one-click Bicep/ARM template in the Azure portal and install the web part from AppSource. No servers to provision, no databases to run, no Power Platform licensing.

Deployed in Minutes Click to enlarge

Microsoft Teams Integration

Work requests, assessments, and approvals from a Teams personal app or channel tab, with activity-feed notifications that deep-link straight back to the record. No context switching, no separate inbox.

Microsoft Teams Integration Click to enlarge

Configured for Your Jurisdiction

Jurisdiction packs preload your statutes, deadlines, exemptions, fees, report templates, and terminology — Canadian ATIP, US FOIA, EU GDPR, UK FOI, and more — so the platform speaks your law from day one. Fee schedules even keep their own currency, never converted, with date format and fiscal year to match.

Configured for Your Jurisdiction Click to enlarge

Multilingual & Accessible

The entire interface ships natively in 11 languages — English and French out of the box for Canadian government. It's built to meet public-sector accessibility standards (WCAG), so everyone can use it.

Multilingual & Accessible Click to enlarge

Watch It Work

Two core workflows, end to end — a public-records request from intake to disclosure, and privacy & AI assessments feeding one risk register.

From request to disclosure
Assessments, breach response & risk

Built for Government

AccessPoint is designed to meet the unique needs of government organizations at every level.

Federal Government

Run ATIA requests, mandatory Algorithmic Impact Assessments, and breach reporting across departments from one platform, with centralized oversight.

Provincial & State Government

Meet FIPPA obligations end to end — including Ontario's Bill 194 mandatory PIAs and AI requirements — with jurisdiction-specific workflows.

Municipal Government

Handle records requests, privacy assessments, and breach notifications with automated workflows sized for smaller teams.

Health, Education & Agencies

Broader-public-sector bodies manage access requests, PIAs, and privacy risk in one auditable system inside their own tenant.

Frequently Asked Questions

How is AccessPoint different from a FOI/ATIP request tool like ATIPXpress, GovQA, AccessPro, or AMANDA's FOI module?

Those tools manage access requests and stop there. AccessPoint manages the full access-and-privacy mandate in one platform — requests plus Privacy Impact Assessments, Algorithmic Impact Assessments, breach notification, complaints, and a privacy risk register — and it runs natively inside your own Microsoft 365 tenant rather than a vendor's cloud. Your data never leaves your control.

How is it different from a privacy platform like OneTrust?

General-purpose privacy suites are built for commercial enterprises and host your data on their own cloud. AccessPoint is purpose-built for public-sector access and privacy, unifies the access (FOI/ATIP) side that those suites don't cover, and deploys into your Microsoft 365 and Azure tenant so you keep full data sovereignty. It operates the work — screeners, section assignment, the live breach-notification calculator, the risk register — rather than handing you a template library.

Does AccessPoint help with Ontario's Bill 194 PIA requirements?

Yes. Since July 1, 2025, FIPPA institutions must complete written Privacy Impact Assessments before collecting personal information, and Bill 194 introduces new AI requirements. AccessPoint's assessment engine runs PIAs and Algorithmic Impact Assessments end to end — screening, questionnaire, risk register, review, and a regulator-ready summary — with a full audit trail.

Can we adopt it just for access requests now and add the privacy modules later?

Yes. Every module shares one platform but is enabled through configuration. Many teams start with ATIP/FOI request management and turn on assessments, incidents, complaints, and the risk register as their privacy program matures — no migration, no new system.

We're on a legacy ATIP/FOI system today — can we bring our history with us?

Yes. Settings → Data import & export generates an Excel template pre-filled with your tenant's own type codes; fill one row per historical request, assessment, incident, or complaint — plus requestors, risks, and vendors — upload it, and read a per-row validation report before anything imports. Legacy case files stage through a pre-provisioned container in your own Azure storage, with optional hash verification for chain of custody. Imported records are historical by construction: no notifications fire, no deadlines recompute, and every record carries an Imported audit-trail entry. The Export tab produces the same workbook back at any time, so you can rehearse against a test tenant first — and you're never locked in.

Where does our data live, and who can see it?

All records, documents, assessments, incidents, and audit history reside in your own Azure and Microsoft 365 tenant. The publisher has no runtime access to your environment. Within your tenant, role-based access control and a PII filter keep custodians and contributors walled off from requestor and data-subject identity.

What about AI — does AccessPoint send our data to an AI service?

Only if you choose to deploy the optional AI Assist components, and even then the Azure OpenAI, AI Search, and OCR resources run inside your own tenant's Azure subscription with managed-identity-only access — nothing goes to the vendor or any third-party AI service, and Microsoft does not train models on your content. Every AI output is a suggestion or an editable draft a person decides on, prompts and responses are never stored, a monthly token budget you control caps all AI processing, and each request's case audit export discloses any AI involvement.

What Microsoft 365 licenses and infrastructure are required?

AccessPoint has no dependency on specific Microsoft 365 licensing tiers and needs no Power Platform or Dataverse licensing. It runs as a SharePoint web part or Teams app against an Azure backend you deploy from a one-click Bicep/ARM template in the Azure portal — App Service, SQL, and Blob storage in your own tenant's subscription. No separate servers to manage.

Are there Azure hosting costs on top of the license?

Yes, and that's by design. AccessPoint runs in your own tenant, so the Azure resources it uses — App Service, Azure SQL, and storage — bill directly to you through Microsoft, typically around $175 per month for a standard configuration and scaling with your size and usage. You pay Microsoft's cost with no vendor markup and control the sizing yourself, unlike SaaS tools that bundle marked-up hosting into per-user fees. It's a fraction of the flat license, and a rounding error next to legacy ATIP software.

Is AccessPoint available in multiple languages?

Yes. The entire interface ships natively in 11 languages — English and French out of the box for Canadian government requirements, plus Danish, Dutch, Finnish, German, Italian, Polish, Portuguese, Spanish, and Swedish. Case content such as scope, correspondence, and closure summaries can also be translated per record, with the original always one click away.

Your Tenant. Your Data. Your Whole Access & Privacy Mandate.

Try AccessPoint free for 30 days. No credit card required.

Start Free Trial