The Microsoft 365-native platform for access, privacy, and responsible AI

AccessPoint runs your whole access-and-privacy program — ATIP and FOI requests, privacy and algorithmic impact assessments, breach response, complaints, and your privacy risk register — inside your own Microsoft 365 tenant. Not a template library. An operating platform where the work actually happens, on your data, under your control.

AccessPoint access and privacy dashboard running in SharePoint

AccessPoint began as an access-to-information request manager and grew into the integrated operating platform for a public-sector access and privacy office. It isn't a suite of separate tools bolted together: every module is configuration-driven and runs on one shared foundation — the same identity, hash-chained audit ledger, review engine, and reporting — so there's a single system to learn, govern, and report on, with no per-user fees.

One Platform, the Whole Mandate

Access requests, privacy assessments, breach response, complaints, and risk — every module sharing one identity, one audit ledger, and one reporting spine.

Access to information requests

The original strength: intake to response for ATIP, FOI, and GDPR requests, built on Microsoft 365.

Integrated with Microsoft 365

Search SharePoint, OneDrive, and Outlook mailboxes and add records straight to a request. Emails are preserved as .eml files with headers and attachments intact. No downloading, re-uploading, or switching applications.

Integrated with Microsoft 365 Click to enlarge

Deadline & Extension Management

Automatic due-date calculation on statutory business-day calendars, with clock pauses, holds, and extension tracking. Never miss a legislative deadline again.

Deadline & Extension Management Click to enlarge

Document Collection & Review

Assign collection tasks to custodians, classify records by relevance, tag and de-duplicate, and track read-through — all in a single faceted workspace with full-text search.

Document Collection & Review Click to enlarge

Redaction & Exemptions

Redact directly in the document viewer. Apply redactions to sections, blocks, or whole pages, tag each with the governing exemption, and assemble a disclosure package with a defensible exemption manifest.

Redaction & Exemptions Click to enlarge

Digital Attestations

Custodians certify their searches and production with legally-defensible digital attestations, captured against the record and backed by the audit ledger.

Digital Attestations Click to enlarge

Privacy & AI impact assessments

Operate PIAs and Algorithmic Impact Assessments end to end — screen, assess, score, review, and publish.

Privacy Impact Assessments (PIA)

Run PIAs, not just fill them in. A configurable questionnaire engine with preliminary screeners, typed questions, an embedded risk register, and a regulator-ready summary export — configured to the assessment mandate that applies to your organization.

Privacy Impact Assessments (PIA) Click to enlarge

Algorithmic Impact Assessments (AIA)

Assess automated decision-making systems against the directive or policy that applies to you — a public-sector AI directive, your own responsible-AI framework, or both. The same engine that runs your PIAs runs your AIAs — scored, tiered, reviewed, and published with an auditable trail.

Algorithmic Impact Assessments (AIA) Click to enlarge

Screeners & Section Delegation

A preliminary screener decides whether a full assessment is even needed. When it is, hand individual sections to subject-matter experts who fill in only their part — answers autosave, and the coordinator merges on approval. No expert ever sees the whole file.

Screeners & Section Delegation Click to enlarge

Records of Processing (ROPA)

Every assessment attaches to a durable privacy subject — a reusable program or system carrying its GDPR Article 30 record: lawful basis, data-subject and recipient categories, retention, safeguards, and cross-border transfers. Export the full ROPA register on demand.

Records of Processing (ROPA) Click to enlarge

Breach & incident management

From discovery to statutory notification, with obligations computed for you.

Incident & Breach Intake

Log a privacy breach in seconds, then work it to closure: cause and circumstances, affected individuals, categories of personal information, containment measures, and a confirmed-contained shield with date and signatory.

Incident & Breach Intake Click to enlarge

Live Breach-Notification Calculator

A real-risk-of-significant-harm evaluation drives a live obligations checklist: who must be told, by when, and what each notice must contain, computed from the incident's legal authority. Mark notices sent, dismiss with a recorded rationale, or generate the letter.

Live Breach-Notification Calculator Click to enlarge

Containment & Remediation

Track corrective and preventive actions as assignable measures with owners, target dates, effectiveness ratings, and a running progress log. Measures are a permanent part of the incident record.

Containment & Remediation Click to enlarge

Complaints & appeals

Track Commissioner complaints and appeals with their own statutory clocks and investigation workspace.

Complaints & Appeals

Track external challenges from a Commissioner or an appeal of a decision. One kind-aware intake handles both, each with its own statutory clock, admissibility check against the filing window, and grounds catalogue — standalone or linked to the request it contests.

Complaints & Appeals Click to enlarge

Investigation & Representations

Delegate evidence-gathering as sanitized workstreams, run the institution's representation through a configurable sign-off, and close with a guided disposition covering findings, judicial review, and order compliance.

Investigation & Representations Click to enlarge

Privacy risk register & commitments

An ISO 31000 register that turns assessment findings into monitored, governed action.

Privacy Risk Register

An ISO 31000 register with inherent and residual scoring, treatment strategies, and governed risk acceptance — over-appetite sign-offs require a justification and an expiry date. Risks surface from assessments and incidents and roll up across your whole program.

Privacy Risk Register Click to enlarge

Key Risk Indicators & Commitments

Monitor risks with Key Risk Indicators — thresholds, RAG status, and a readings history — and track the privacy commitments that come out of an assessment to completion, with recurring check-ins so nothing is forgotten.

Key Risk Indicators & Commitments Click to enlarge

One governed platform

The shared spine every module runs on — configure it once, reuse it everywhere.

Review & Approval Workflows

One configurable review engine — sequential or parallel stages, gating, and reminders — approves redactions, sign-off on an assessment, representations on a complaint, and more. Configure it once; reuse it everywhere.

Review & Approval Workflows Click to enlarge

Hash-Chained Audit Ledger

Every action across every module is written to an append-only, hash-chained ledger with integrity verification — and exported as court-ready evidence packages. Nothing is edited away; the record proves itself.

Hash-Chained Audit Ledger Click to enlarge

Reporting & Custom Report Builder

Statutory annual-report templates, fixed operational reports, SLA and workload dashboards, and a custom report builder — choose a subject, groupings, measures, and filters, then save and export.

Reporting & Custom Report Builder Click to enlarge

Role-Based Dashboards & My Day

Every role gets a purpose-built view — Senior Access Officers see the whole picture, custodians see only their assignments — and a computed My Day list tells each person exactly what needs attention next.

Role-Based Dashboards & My Day Click to enlarge

Consultations & Correspondence

Run inter-departmental and third-party consultations with their own statutory windows, and compose templated, token-merged correspondence that passes through a PII firewall so the right people see the right details.

Consultations & Correspondence Click to enlarge

Native to Microsoft 365

Your tenant, your data, your compliance — with no new infrastructure to run.

Data Sovereignty

Requests, documents, assessments, incidents, and audit history stay in your Microsoft 365 and Azure tenant and never leave your control. No third-party cloud, no cross-border transfers, no vendor access to your data.

Data Sovereignty Click to enlarge

Enterprise Security

Authentication through your existing Microsoft Entra ID — no new passwords. Server-side role-based access control, a PII filter that walls custodians and contributors off from requestor identity, TLS 1.3, and Entra-only database authentication.

Enterprise Security Click to enlarge

Deployed in Minutes

Deploy the Azure backend from a one-click Bicep/ARM template in the Azure portal and install the web part from AppSource. No servers to provision, no databases to run, no Power Platform licensing.

Deployed in Minutes Click to enlarge

Microsoft Teams Integration

Work requests, assessments, and approvals from a Teams personal app or channel tab, with activity-feed notifications that deep-link straight back to the record. No context switching, no separate inbox.

Microsoft Teams Integration Click to enlarge

Configured for Your Jurisdiction

Configuration packs preload your jurisdiction's statutes, deadline rules, exemptions, fees, notification regimes, and terminology — Canadian ATIP (federal and provincial), US FOIA, EU GDPR, UK FOI, Australian FOI, and more — so the platform speaks your law from day one.

Configured for Your Jurisdiction Click to enlarge

Multilingual & Accessible

The entire interface ships natively in 11 languages — English and French out of the box for Canadian government. It's built to meet public-sector accessibility standards (WCAG), so everyone can use it.

Multilingual & Accessible Click to enlarge

Watch It Work

Two core workflows, end to end — a public-records request from intake to disclosure, and privacy & AI assessments feeding one risk register.

From request to disclosure
Assessments, breach response & risk

Built for Government

AccessPoint is designed to meet the unique needs of government organizations at every level.

Federal Government

Run ATIA requests, mandatory Algorithmic Impact Assessments, and breach reporting across departments from one platform, with centralized oversight.

Provincial & State Government

Meet FIPPA obligations end to end — including Ontario's Bill 194 mandatory PIAs and AI requirements — with jurisdiction-specific workflows.

Municipal Government

Handle records requests, privacy assessments, and breach notifications with automated workflows sized for smaller teams.

Health, Education & Agencies

Broader-public-sector bodies manage access requests, PIAs, and privacy risk in one auditable system inside their own tenant.

Frequently Asked Questions

How is AccessPoint different from a FOI/ATIP request tool like ATIPXpress or GovQA?

Those tools manage access requests and stop there. AccessPoint manages the full access-and-privacy mandate in one platform — requests plus Privacy Impact Assessments, Algorithmic Impact Assessments, breach notification, complaints, and a privacy risk register — and it runs natively inside your own Microsoft 365 tenant rather than a vendor's cloud. Your data never leaves your control.

How is it different from a privacy platform like OneTrust?

General-purpose privacy suites are built for commercial enterprises and host your data on their own cloud. AccessPoint is purpose-built for public-sector access and privacy, unifies the access (FOI/ATIP) side that those suites don't cover, and deploys into your Microsoft 365 and Azure tenant so you keep full data sovereignty. It operates the work — screeners, section delegation, the live breach-notification calculator, the risk register — rather than handing you a template library.

Does AccessPoint help with Ontario's Bill 194 PIA requirements?

Yes. Since July 1, 2025, FIPPA institutions must complete written Privacy Impact Assessments before collecting personal information, and Bill 194 introduces new AI requirements. AccessPoint's assessment engine runs PIAs and Algorithmic Impact Assessments end to end — screening, questionnaire, risk register, review, and a regulator-ready summary — with a full audit trail.

Can we adopt it just for access requests now and add the privacy modules later?

Yes. Every module shares one platform but is enabled through configuration. Many teams start with ATIP/FOI request management and turn on assessments, incidents, complaints, and the risk register as their privacy program matures — no migration, no new system.

Where does our data live, and who can see it?

All records, documents, assessments, incidents, and audit history reside in your own Azure and Microsoft 365 tenant. The publisher has no runtime access to your environment. Within your tenant, role-based access control and a PII filter keep custodians and contributors walled off from requestor and data-subject identity.

What Microsoft 365 licenses and infrastructure are required?

AccessPoint has no dependency on specific Microsoft 365 licensing tiers and needs no Power Platform or Dataverse licensing. It runs as a SharePoint web part or Teams app against an Azure backend you deploy from a one-click Bicep/ARM template in the Azure portal — App Service, SQL, and Blob storage in your own subscription. No separate servers to manage.

Are there Azure hosting costs on top of the license?

Yes, and that's by design. AccessPoint runs in your own tenant, so the Azure resources it uses — App Service, Azure SQL, and storage — bill directly to you through Microsoft, typically around $175 per month for a standard configuration and scaling with your size and usage. You pay Microsoft's cost with no vendor markup and control the sizing yourself, unlike SaaS tools that bundle marked-up hosting into per-user fees. It's a fraction of the flat license, and a rounding error next to legacy ATIP software.

Is AccessPoint available in multiple languages?

Yes. AccessPoint is 100% multilingual. It ships bilingual (English/French) for Canadian government requirements and supports unlimited additional languages — every interface element, notice, and workflow can be localized.

Your Tenant. Your Data. Your Whole Access & Privacy Mandate.

Try AccessPoint free for 30 days. No credit card required.

Start Free Trial