How the four case types (requests, assessments, incidents, complaints) share one spine — their lifecycle stages, who does what, and where the work lives

Last updated: July 30, 2026 by Steve

Case Workflows: Process & Actors

AccessPoint handles four kinds of case work — access requests, privacy assessments, privacy incidents, and complaints/appeals. They look different on the surface, but they are built on one shared spine, so a coordinator who learns one recognises the others.

This page is the map: the stages each case type moves through, who does the work, and where in the product it lives. Use it to orient a new team, and to compare AccessPoint against your office's existing SOP — most offices find their process maps onto these stages with different names, which is exactly what the configuration layer is for.

Nothing here is a legal standard. Statutory deadlines, mandatory steps, and who may sign off vary by jurisdiction and are configured per tenant (request types, legal authorities, review workflows, deadline rules). The stages below are the workflow AccessPoint enforces; the rules are yours.

The Shared Spine

Every case type has the same underlying anatomy:

Element What it is
Lifecycle stages A small, fixed set of stages shown as a rail across the top of the case. Statuses within a stage are configurable; the stages themselves are the engine.
An owner One accountable person (access officer, assessment owner, privacy officer, complaint officer). Delegation can cover their work temporarily without transferring ownership.
Delegated work The owner parcels work out: custodian assignments and contributor tasks (requests), section assignments (assessments), workstreams (complaints). Each has its own submit → review cycle.
Documents A workspace per case, with PDF conversion, tagging, duplicate detection, and — where disclosure applies — redaction and response packaging.
Correspondence Inbound and outbound communication tied to the case, with templates and a PII firewall for roles that must not see requestor identity.
Reviews & approvals Optional configurable review workflows that gate a case (or a piece of work) before it proceeds.
Closure & reporting A closure step that captures the outcome, then feeds the statistical and management reports.

Who's Who

Roles are described in the User Guide overview; this is how they typically show up across the four case types.

Role Access requests Assessments Incidents Complaints
Administrator Configures types, deadlines, templates, packs Configures templates + types Configures types + notification rules Configures types + clocks
Access/privacy officer Owns the request end to end Usually owns the assessment Usually owns the incident Owns the complaint file
Reviewer / legal Reviews proposed disclosure + exemptions Reviews and approves Reviews findings + notification decision Reviews representations
Custodian Searches their holdings, attests Supplies facts for their area
Contributor Works a task under a custodian
Assignee Completes a delegated section Completes a workstream
Reader / Advisor Read-only on associated cases Read-only Read-only Read-only

Custodians and contributors work from sanitized instructions and never see requestor identity — that privacy boundary holds across every case type.

The Four Lifecycles

Each case type moves through its own small set of stages. Statuses within a stage are yours to configure.

Case type Stages Delegated work unit Where it lives
Access request Draft → Active → In Review → Closed · On Hold pauses the clock Custodian assignments → contributor tasks Requests
Assessment (PIA/AIA/Security) Active → In Review → In Effect → Closed Section assignments to subject-matter experts Assessments
Incident / breach Active → In Review → Closed Containment & remediation measures Incidents
Complaint / appeal Active → In Review → Submitted → Closed Investigation workstreams Complaints

Access requests in practice. A request arrives by mail, email, or portal; the officer creates it (New from email pulls an email straight in). The requestor is matched to a reusable contact. Type and jurisdiction set the deadline rules, and activating starts the clock. The officer raises custodian assignments with sanitized instructions; custodians search, upload, mark relevance, and attest; the officer approves or requests changes. Records convert to PDF and enter the Documents workspace for exemption review and redaction, with third-party consultations and extensions where the statute permits. A configurable review workflow can gate the package before release, and closure records the disposition and feeds the reports.

The Registers Cases Feed

Two cross-case registers collect what the case types produce:

  • Risks — an assessment or incident can raise entries on the ISO 31000 privacy risk register; a risk can also stand alone.
  • Commitments — recommendations from an assessment or complaint are tracked to completion as commitments.

Because every case type shares the spine, once you have worked one you can work them all — and the Ask AccessPoint assistant (when AI Assist is deployed) can answer "what's outstanding on this case?" the same way on any of them.