How the four case types (requests, assessments, incidents, complaints) share one spine — their lifecycle stages, who does what, and where the work lives
Last updated: July 30, 2026 by Steve
Case Workflows: Process & Actors
AccessPoint handles four kinds of case work — access requests, privacy assessments, privacy incidents, and complaints/appeals. They look different on the surface, but they are built on one shared spine, so a coordinator who learns one recognises the others.
This page is the map: the stages each case type moves through, who does the work, and where in the product it lives. Use it to orient a new team, and to compare AccessPoint against your office's existing SOP — most offices find their process maps onto these stages with different names, which is exactly what the configuration layer is for.
Nothing here is a legal standard. Statutory deadlines, mandatory steps, and who may sign off vary by jurisdiction and are configured per tenant (request types, legal authorities, review workflows, deadline rules). The stages below are the workflow AccessPoint enforces; the rules are yours.
The Shared Spine
Every case type has the same underlying anatomy:
| Element | What it is |
|---|---|
| Lifecycle stages | A small, fixed set of stages shown as a rail across the top of the case. Statuses within a stage are configurable; the stages themselves are the engine. |
| An owner | One accountable person (access officer, assessment owner, privacy officer, complaint officer). Delegation can cover their work temporarily without transferring ownership. |
| Delegated work | The owner parcels work out: custodian assignments and contributor tasks (requests), section assignments (assessments), workstreams (complaints). Each has its own submit → review cycle. |
| Documents | A workspace per case, with PDF conversion, tagging, duplicate detection, and — where disclosure applies — redaction and response packaging. |
| Correspondence | Inbound and outbound communication tied to the case, with templates and a PII firewall for roles that must not see requestor identity. |
| Reviews & approvals | Optional configurable review workflows that gate a case (or a piece of work) before it proceeds. |
| Closure & reporting | A closure step that captures the outcome, then feeds the statistical and management reports. |
Who's Who
Roles are described in the User Guide overview; this is how they typically show up across the four case types.
| Role | Access requests | Assessments | Incidents | Complaints |
|---|---|---|---|---|
| Administrator | Configures types, deadlines, templates, packs | Configures templates + types | Configures types + notification rules | Configures types + clocks |
| Access/privacy officer | Owns the request end to end | Usually owns the assessment | Usually owns the incident | Owns the complaint file |
| Reviewer / legal | Reviews proposed disclosure + exemptions | Reviews and approves | Reviews findings + notification decision | Reviews representations |
| Custodian | Searches their holdings, attests | — | Supplies facts for their area | — |
| Contributor | Works a task under a custodian | — | — | — |
| Assignee | — | Completes a delegated section | — | Completes a workstream |
| Reader / Advisor | Read-only on associated cases | Read-only | Read-only | Read-only |
Custodians and contributors work from sanitized instructions and never see requestor identity — that privacy boundary holds across every case type.
The Four Lifecycles
Each case type moves through its own small set of stages. Statuses within a stage are yours to configure.
| Case type | Stages | Delegated work unit | Where it lives |
|---|---|---|---|
| Access request | Draft → Active → In Review → Closed · On Hold pauses the clock | Custodian assignments → contributor tasks | Requests |
| Assessment (PIA/AIA/Security) | Active → In Review → In Effect → Closed | Section assignments to subject-matter experts | Assessments |
| Incident / breach | Active → In Review → Closed | Containment & remediation measures | Incidents |
| Complaint / appeal | Active → In Review → Submitted → Closed | Investigation workstreams | Complaints |
Access requests in practice. A request arrives by mail, email, or portal; the officer creates it (New from email pulls an email straight in). The requestor is matched to a reusable contact. Type and jurisdiction set the deadline rules, and activating starts the clock. The officer raises custodian assignments with sanitized instructions; custodians search, upload, mark relevance, and attest; the officer approves or requests changes. Records convert to PDF and enter the Documents workspace for exemption review and redaction, with third-party consultations and extensions where the statute permits. A configurable review workflow can gate the package before release, and closure records the disposition and feeds the reports.
The Registers Cases Feed
Two cross-case registers collect what the case types produce:
- Risks — an assessment or incident can raise entries on the ISO 31000 privacy risk register; a risk can also stand alone.
- Commitments — recommendations from an assessment or complaint are tracked to completion as commitments.
Because every case type shares the spine, once you have worked one you can work them all — and the Ask AccessPoint assistant (when AI Assist is deployed) can answer "what's outstanding on this case?" the same way on any of them.