The Microsoft 365-native platform for access, privacy, and responsible AI
AccessPoint runs your whole access-and-privacy program — ATIP and FOI requests, privacy and algorithmic impact assessments, breach response, complaints, and your privacy risk register — inside your own Microsoft 365 tenant. Not a template library. An operating platform where the work actually happens, on your data, under your control.
AccessPoint began as an access-to-information request manager and grew into the integrated operating platform for a public-sector access and privacy office. It isn't a suite of separate tools bolted together: every module is configuration-driven and runs on one shared foundation — the same identity, hash-chained audit ledger, review engine, and reporting — so there's a single system to learn, govern, and report on, with no per-user fees.
One Platform, the Whole Mandate
Access requests, privacy assessments, breach response, complaints, and risk — every module sharing one identity, one audit ledger, and one reporting spine.
Access to information requests
The original strength: intake to response for ATIP, FOI, and GDPR requests, built on Microsoft 365.
Integrated with Microsoft 365
Search SharePoint, OneDrive, and Outlook mailboxes and add records straight to a request. Emails are preserved as .eml files with headers and attachments intact. No downloading, re-uploading, or switching applications.
Deadline & Extension Management
Automatic due-date calculation on statutory business-day calendars, with clock pauses, holds, and extension tracking. Never miss a legislative deadline again.
Document Collection & Review
Assign collection tasks to custodians, classify records by relevance, tag and de-duplicate, and track read-through — all in a single faceted workspace with full-text search.
Redaction & Exemptions
Redact directly in the document viewer. Apply redactions to sections, blocks, or whole pages, tag each with the governing exemption, and assemble a disclosure package with a defensible exemption manifest.
Digital Attestations
Custodians certify their searches and production with legally-defensible digital attestations, captured against the record and backed by the audit ledger.
Privacy & AI impact assessments
Operate PIAs and Algorithmic Impact Assessments end to end — screen, assess, score, review, and publish.
Privacy Impact Assessments (PIA)
Run PIAs, not just fill them in. A configurable questionnaire engine with preliminary screeners, typed questions, an embedded risk register, and a regulator-ready summary export — configured to the assessment mandate that applies to your organization.
Algorithmic Impact Assessments (AIA)
Assess automated decision-making systems against the directive or policy that applies to you — a public-sector AI directive, your own responsible-AI framework, or both. The same engine that runs your PIAs runs your AIAs — scored, tiered, reviewed, and published with an auditable trail.
Screeners & Section Delegation
A preliminary screener decides whether a full assessment is even needed. When it is, hand individual sections to subject-matter experts who fill in only their part — answers autosave, and the coordinator merges on approval. No expert ever sees the whole file.
Records of Processing (ROPA)
Every assessment attaches to a durable privacy subject — a reusable program or system carrying its GDPR Article 30 record: lawful basis, data-subject and recipient categories, retention, safeguards, and cross-border transfers. Export the full ROPA register on demand.
Breach & incident management
From discovery to statutory notification, with obligations computed for you.
Incident & Breach Intake
Log a privacy breach in seconds, then work it to closure: cause and circumstances, affected individuals, categories of personal information, containment measures, and a confirmed-contained shield with date and signatory.
Live Breach-Notification Calculator
A real-risk-of-significant-harm evaluation drives a live obligations checklist: who must be told, by when, and what each notice must contain, computed from the incident's legal authority. Mark notices sent, dismiss with a recorded rationale, or generate the letter.
Containment & Remediation
Track corrective and preventive actions as assignable measures with owners, target dates, effectiveness ratings, and a running progress log. Measures are a permanent part of the incident record.
Complaints & appeals
Track Commissioner complaints and appeals with their own statutory clocks and investigation workspace.
Complaints & Appeals
Track external challenges from a Commissioner or an appeal of a decision. One kind-aware intake handles both, each with its own statutory clock, admissibility check against the filing window, and grounds catalogue — standalone or linked to the request it contests.
Investigation & Representations
Delegate evidence-gathering as sanitized workstreams, run the institution's representation through a configurable sign-off, and close with a guided disposition covering findings, judicial review, and order compliance.
Privacy risk register & commitments
An ISO 31000 register that turns assessment findings into monitored, governed action.
Privacy Risk Register
An ISO 31000 register with inherent and residual scoring, treatment strategies, and governed risk acceptance — over-appetite sign-offs require a justification and an expiry date. Risks surface from assessments and incidents and roll up across your whole program.
Key Risk Indicators & Commitments
Monitor risks with Key Risk Indicators — thresholds, RAG status, and a readings history — and track the privacy commitments that come out of an assessment to completion, with recurring check-ins so nothing is forgotten.
One governed platform
The shared spine every module runs on — configure it once, reuse it everywhere.
Review & Approval Workflows
One configurable review engine — sequential or parallel stages, gating, and reminders — approves redactions, sign-off on an assessment, representations on a complaint, and more. Configure it once; reuse it everywhere.
Hash-Chained Audit Ledger
Every action across every module is written to an append-only, hash-chained ledger with integrity verification — and exported as court-ready evidence packages. Nothing is edited away; the record proves itself.
Reporting & Custom Report Builder
Statutory annual-report templates, fixed operational reports, SLA and workload dashboards, and a custom report builder — choose a subject, groupings, measures, and filters, then save and export.
Role-Based Dashboards & My Day
Every role gets a purpose-built view — Senior Access Officers see the whole picture, custodians see only their assignments — and a computed My Day list tells each person exactly what needs attention next.
Consultations & Correspondence
Run inter-departmental and third-party consultations with their own statutory windows, and compose templated, token-merged correspondence that passes through a PII firewall so the right people see the right details.
Native to Microsoft 365
Your tenant, your data, your compliance — with no new infrastructure to run.
Data Sovereignty
Requests, documents, assessments, incidents, and audit history stay in your Microsoft 365 and Azure tenant and never leave your control. No third-party cloud, no cross-border transfers, no vendor access to your data.
Enterprise Security
Authentication through your existing Microsoft Entra ID — no new passwords. Server-side role-based access control, a PII filter that walls custodians and contributors off from requestor identity, TLS 1.3, and Entra-only database authentication.
Deployed in Minutes
Deploy the Azure backend from a one-click Bicep/ARM template in the Azure portal and install the web part from AppSource. No servers to provision, no databases to run, no Power Platform licensing.
Microsoft Teams Integration
Work requests, assessments, and approvals from a Teams personal app or channel tab, with activity-feed notifications that deep-link straight back to the record. No context switching, no separate inbox.
Configured for Your Jurisdiction
Configuration packs preload your jurisdiction's statutes, deadline rules, exemptions, fees, notification regimes, and terminology — Canadian ATIP (federal and provincial), US FOIA, EU GDPR, UK FOI, Australian FOI, and more — so the platform speaks your law from day one.
Multilingual & Accessible
The entire interface ships natively in 11 languages — English and French out of the box for Canadian government. It's built to meet public-sector accessibility standards (WCAG), so everyone can use it.
Watch It Work
Two core workflows, end to end — a public-records request from intake to disclosure, and privacy & AI assessments feeding one risk register.
Built for Government
AccessPoint is designed to meet the unique needs of government organizations at every level.
Federal Government
Run ATIA requests, mandatory Algorithmic Impact Assessments, and breach reporting across departments from one platform, with centralized oversight.
Provincial & State Government
Meet FIPPA obligations end to end — including Ontario's Bill 194 mandatory PIAs and AI requirements — with jurisdiction-specific workflows.
Municipal Government
Handle records requests, privacy assessments, and breach notifications with automated workflows sized for smaller teams.
Health, Education & Agencies
Broader-public-sector bodies manage access requests, PIAs, and privacy risk in one auditable system inside their own tenant.
Frequently Asked Questions
How is AccessPoint different from a FOI/ATIP request tool like ATIPXpress or GovQA?
How is it different from a privacy platform like OneTrust?
Does AccessPoint help with Ontario's Bill 194 PIA requirements?
Can we adopt it just for access requests now and add the privacy modules later?
Where does our data live, and who can see it?
What Microsoft 365 licenses and infrastructure are required?
Are there Azure hosting costs on top of the license?
Is AccessPoint available in multiple languages?
Your Tenant. Your Data. Your Whole Access & Privacy Mandate.
Try AccessPoint free for 30 days. No credit card required.
Start Free Trial