Solutions · By capability

FOI request management software that runs the whole lifecycle

Intake to disclosure: statutory deadlines computed from your legislation, records collected straight from Microsoft 365, redaction with exemption tagging in the browser, and every action on a court-ready audit ledger — in your own tenant.

FOI request management software exists because the work is unforgiving: statutory clocks that run on business-day calendars, exemptions that must be applied line by line and defended later, records scattered across mailboxes and drives, and an oversight body that will eventually ask you to prove every step. A spreadsheet can log requests; it can't compute a deemed-refusal date, wall custodians off from requestor identity, or produce an audit trail a commissioner will accept.

Most FOI tools solve the logging layer and stop — a register with reminders, and the real work still happening in email, desktop redaction tools, and shared folders. AccessPoint's approach is to operate the whole lifecycle in one governed system: the request, its clock, the records, the review, the redactions, the correspondence, and the release package, each step feeding the same hash-chained audit ledger.

And because it's Microsoft 365-native, the biggest hidden cost of FOI software disappears: your responsive records already live in SharePoint, Outlook, and Teams. AccessPoint collects them where they are, instead of your team downloading and re-uploading them into a separate vendor cloud.

What to look for in FOI request management software

Whatever you buy — including if it isn't AccessPoint — these are the capabilities that separate a request register from a system that actually carries the work.

Statutory deadline math, not reminders Due dates computed on your statute's business-day calendar, with clock pauses, extensions, holds — and the statutory consequence (deemed refusal) recorded automatically when a date passes.
Collection from where records live If staff must export records from email and SharePoint and upload them into the tool, every request pays that tax. Look for native collection from your actual repositories.
Redaction with statutory exemption tagging Every severance should carry its legal authority — primary and fall-back exemptions — so the disclosure package ships with a defensible exemption manifest, not just black boxes.
A PII firewall inside the workflow Custodians searching for records shouldn't see who asked. Role separation between coordinators, custodians, and reviewers should be enforced by the system, not by discipline.
An audit trail that proves itself When a decision is challenged, application logs aren't evidence. An append-only, tamper-evident ledger of every action is.
Your jurisdiction's rules, preloaded Deadlines, exemption catalogues, fee rules, statutory report formats — and the currency, date format and fiscal year those run on — all differ by statute. Jurisdiction packs beat months of consulting hours.

How AccessPoint runs the request lifecycle

One governed platform from intake to release — these are the load-bearing pieces.

Intake in one step

An email in your intake mailbox becomes a fully-formed request with the message attached as its first document — or log requests manually with AI triage suggesting title, summary, scope, and clarification questions to send.

Deadlines you never compute

Statutory business-day calendars drive every due date, with extensions, fee-deposit clock pauses, and holds tracked against their legal basis — and deemed refusal recorded automatically if a date passes unanswered.

Collection, review & attestations

Assign collection tasks to custodians, pull records straight from SharePoint, OneDrive, Outlook, and Teams, de-duplicate with per-copy decisions, and close searches with legally-defensible digital attestations.

Redaction in the browser

A full redaction studio — find-and-redact across documents, exemption tagging with fall-backs, live patterns on newly arriving records, and optional AI-proposed redactions into the same human review pipeline.

Consultations & correspondence

Third-party and inter-departmental consultations with their own statutory windows, and templated letters built from merge fields that pass through a PII firewall.

Reporting your oversight body expects

Statutory annual-report templates from your jurisdiction pack, operational dashboards, and Report Studio for everything leadership asks that the statute doesn't.

The structural difference

Your requests never leave your tenant

The records under FOI review are among the most sensitive your organization holds — that's why they're being reviewed. AccessPoint processes them inside your own Microsoft 365 and Azure environment, not a vendor's cloud.

Tenant-resident by architecture The database, documents, and audit history live in your Azure subscription, governed by your existing security stack.
Your identity, your controls Entra ID authentication, server-side role enforcement, and no vendor runtime access to your environment.
Flat, public pricing Per-organization annual pricing published on the site — no per-user fees, no call-for-quote cycle, billed through the Microsoft marketplace.

FOI Request Management Questions

What does FOI request management software actually do?

At minimum it tracks requests against statutory deadlines. Done properly, it operates the full lifecycle: intake and acknowledgement, due-date computation on business-day calendars with extensions and clock pauses, records collection and custodian tasking, relevance review and de-duplication, redaction with statutory exemption tagging, third-party consultations, fee handling, correspondence, the release package, and the statistical reports your oversight body requires — with an audit trail behind every step. AccessPoint covers that whole span, plus the privacy side of the same office (PIAs, breaches, complaints, risk).

How is AccessPoint different from other FOI software?

Two structural choices. First, it's Microsoft 365-native: it runs inside your own tenant and collects responsive records directly from SharePoint, OneDrive, Outlook, and Teams, so your most sensitive documents never move to a vendor cloud. Second, it covers the whole mandate — the same platform runs privacy impact assessments, breach response, complaints, and a privacy risk register on one shared audit ledger. Pricing is flat per organization and published on the site.

Can it handle our specific statute's deadlines and exemptions?

That's what jurisdiction packs are for: 106 of them, covering Canadian federal ATIP and every province, US federal FOIA and two dozen states, EU GDPR, UK FOI, and more. A pack preloads response deadlines, business-day calendars, exemption catalogues with citations, fee rules, letter templates, and the statutory report formats your regulator expects — as a starting point you can adjust, not a lock-in.

We track FOI requests in a spreadsheet today. When does software become worth it?

The honest threshold isn't request count — it's risk and rework. When deadline math gets manual enough to miss, when redaction happens in desktop tools with no exemption record, when a commissioner's review would mean reconstructing history from email threads, the spreadsheet is costing more than software. The ROI calculator on this site lets you estimate it for your volumes, and a guided import brings your spreadsheet history in — nothing is lost.

Does AI do the redaction and drafting?

Only if you turn it on, and never on its own. AI Assist is optional and runs on Azure OpenAI inside your own tenant's Azure subscription — it can propose redactions with reasons and confidence scores, draft letters grounded on the record's facts, and triage intake, but every output lands in a human review pipeline. Nothing is applied automatically, prompts and responses are never stored, and nothing trains an outside model.

Run FOI Like It's 2026, Not 2006.

Try AccessPoint free for 30 days in your own Microsoft 365 tenant — configured for your jurisdiction from day one.

Start Free Trial