Solutions · By organization

Full statutory obligations. A part-time coordinator. Software that closes the gap.

US independent agencies, authorities, and special districts; UK arm's-length bodies and non-departmental public bodies; Canadian agencies, boards, and commissions; plus tribunals, regulators, and Crown corporations — all answer the same access, privacy, and breach-reporting duties as a full department, without a department's staff. AccessPoint preloads your statute, computes every deadline, and writes every action to a tamper-evident audit ledger, inside the Microsoft 365 tenant you already have.

Access and privacy statutes don't scale their obligations to your headcount. Whatever your jurisdiction calls you — a US independent agency, authority, or special district; a UK arm's-length body or non-departmental public body (NDPB); a Canadian agency, board, or commission; a tribunal, a regulator, or a Crown corporation — if the statute designates you, you carry the full mandate. Statutory response clocks, exemptions applied correctly, privacy impact assessments, breach reporting: the same duties, whether you're a forty-person office or a coordinator who does this on Thursdays. AccessPoint is built for the second case: your jurisdiction's rules preloaded from a jurisdiction pack, deadlines computed automatically, a one-click deployment into the Microsoft 365 tenant your organization already runs on, and a flat USD $2,990 entry price with no per-user fees.

The typical arm's-length file looks the same in every country. The coordinator inherited the role alongside another job, the process lives in one person's memory and an inbox, there's no dedicated IT team to stand up or maintain software, and volumes are low enough that nothing feels urgent — until a request lands with a clock attached, or a breach does. The risk isn't volume; it's exposure. One mishandled request or unreported incident at an arm's-length body draws exactly the kind of scrutiny these institutions exist to avoid, and the statute grades you against the same standard as the largest department.

What a department solves with organizational depth, a small body has to solve with software. That mismatch — full obligations, fractional staffing — is not a Commonwealth quirk; it is the universal shape of this sector. AccessPoint's 106 jurisdiction packs stand in for the access-law specialist you didn't hire — deadlines, exemption catalogues, fee rules, letters, and statutory report formats preloaded for your regime. Deadline automation and computed breach checklists stand in for the second set of eyes. And the hash-chained audit ledger stands in for institutional memory, so when the mandate review, audit, or commissioner's inquiry arrives, the record is already built — not reconstructed from an inbox.

What an arm's-length body needs from access and privacy software

Whatever you choose — including if it isn't AccessPoint — hold it to this list. These are the capabilities that substitute for the organizational depth a small body doesn't have.

Your statute preloaded Your state's public-records law, UK FOIA and the Environmental Information Regulations, UK GDPR subject access, a Canadian access statute — the deadlines, exemption catalogues, fee rules, and letter templates should arrive as configuration, not as a consulting engagement your budget can't carry.
Deadlines that compute themselves Business-day, working-day, or calendar-day math on the right calendar, extensions tracked against their legal basis, and the statutory consequence recorded automatically — a part-time coordinator cannot watch a clock daily, so the system must.
Deployment without an IT department It should install into infrastructure you already have, with no servers to run and no new platform to learn — because there's no one to run them.
Security you inherit, not assess Sign-in through your existing identity provider, roles enforced by the system, and data that stays in an environment you already govern — one less vendor review for an office with no security team.
A record built for accountability reviews Arm's-length bodies face mandate reviews, audits, and oversight inquiries. An append-only, tamper-evident trail of every action means the answer to "show us how this was handled" already exists.
Continuity through turnover When the coordinator role changes hands — and in a small body it will — the process, the history, and the open work should live in the system, with a one-step handoff, not in a departed person's memory.

How AccessPoint stands in for the org depth

One platform running the whole mandate — requests, assessments, breaches, complaints — sized so one coordinator can actually operate it.

Jurisdiction packs — 106 of them

US state and local records laws (27 packs, including a rebindable baseline for the rest), UK FOIA 2000, EIR 2004, and UK GDPR, Canadian federal and provincial regimes, EU GDPR, and more — each preloading your statute's deadlines, exemptions, fees, correspondence templates, and the report formats your oversight body expects.

The clock watches itself

Due dates computed on the statutory calendar your regime uses, with extensions, holds, and clock pauses tracked — and the statutory consequence recorded automatically if a date passes unanswered. Nothing depends on someone remembering.

Breach duties, computed

Log an incident in seconds, assess the risk of significant harm, and work a live checklist of who must be notified, by when, and what each notice must contain — computed from the incident's legal authority, not from memory under pressure.

My Day, for a part-time schedule

Open AccessPoint on the day you do this work and a computed My Day list shows exactly what moved and what's due — and when you're away, the whole caseload delegates in one step.

Deployed in minutes, not projects

A one-click Bicep/ARM template deploys the Azure backend into your own tenant's subscription; the web part installs from AppSource; sign-in is your existing Microsoft Entra ID. No servers, no Power Platform licensing, no new passwords.

An audit trail that survives you

Every action across every module lands on an append-only, hash-chained ledger with integrity verification — exportable as court-ready case audit records for the reviews these bodies face.

Accountability without the overhead

When the review comes, the record is already built

Arm's-length bodies live under a particular kind of scrutiny: mandate reviews, auditors, commissioner investigations, and the standing question of whether a small institution is meeting obligations written for large ones. AccessPoint's answer is structural — every action on every request, assessment, and incident is written to an append-only, hash-chained audit ledger, and exported on demand as a court-ready case record. You don't reconstruct history from an inbox; you produce it.

Tamper-evident by construction Hash-chained and append-only, with integrity verification — nothing is edited away.
Attestations and sign-offs Searches close with legally-defensible digital attestations, and approvals run through a configurable review workflow rather than a forwarded email.
Evidence in your own tenant The record lives in your Microsoft 365 and Azure environment, governed by your own controls, with no vendor access.

Standing it up without an IT department

AccessPoint deploys into the Microsoft 365 your organization already has. One administrator afternoon covers it:

  1. Start the 30-day free trial — billing, if you continue, runs through the Microsoft commercial marketplace your organization already procures from.
  2. Deploy the Azure backend from a one-click template in the Azure portal — App Service, database, and storage in your own tenant's subscription, typically around $175 per month.
  3. Install the web part from AppSource and sign in with your existing Microsoft Entra ID — no new passwords, no new vendor accounts.
  4. Apply your jurisdiction pack — your state's records law, UK FOIA and EIR, a Canadian access statute — to preload deadlines, exemptions, fees, and letter templates.
  5. Log your open requests — or import your history from a spreadsheet with the validated Excel workbook — and let the clocks compute.

Agencies, Boards & Commissions Questions

Do small agencies, special districts, and arm's-length bodies have the same obligations as a full department?

Where the statute designates you, yes — obligations attach to the institution, not its headcount. The UK's Freedom of Information Act 2000 reaches recorded information held by public authorities, which is how arm's-length bodies and NDPBs end up on the 20-working-day clock. The California Public Records Act covers state and local agencies alike, which is how authorities and special districts end up on the 10-day determination window. Ontario's FIPPA covers provincial agencies alongside ministries and universities, and MFIPPA covers local boards and police services boards alongside municipalities. The response clocks, exemption rules, and reporting duties are the same ones the largest institutions answer. That mismatch — full obligations, fractional staffing — is exactly the problem AccessPoint is sized for.

How can a part-time coordinator keep up with statutory deadlines?

By not keeping them up personally. AccessPoint computes every due date on your statute's own calendar — business days, working days, or calendar days as the regime requires — tracks extensions and clock pauses against their legal basis, and records the statutory consequence automatically if a date passes. A computed My Day list shows what needs attention on the days you do this work, so a part-time schedule doesn't mean part-time compliance.

We don't have an IT department — can we still run AccessPoint?

Yes. The Azure backend deploys from a one-click template in the Azure portal, the web part installs from AppSource, and sign-in is your existing Microsoft Entra ID — no servers to maintain, no Power Platform licensing, and no new passwords. You'll need a Microsoft 365 / Azure administrator for the initial setup, which many small bodies borrow from their parent department or IT provider for an afternoon. After that, the publisher has no runtime access to your environment, and Azure hosting runs about $175 per month in your own tenant's subscription.

What does access and privacy software cost for a small agency?

AccessPoint is a flat USD $2,990 per year at the entry tier — $7,990 and $14,990 for larger organizations — with every feature in every tier and no per-user fees. It's billed through the Microsoft commercial marketplace, there's a 30-day free trial, and the only other cost is the Azure hosting in your own tenant's subscription. No call-for-quote cycle, no seat counting.

How does AccessPoint help with audits and accountability reviews?

Every action across requests, assessments, incidents, and complaints is written to an append-only, hash-chained audit ledger with integrity verification, and any case can be exported as a court-ready audit record. Custodian searches close with digital attestations, approvals run through recorded review workflows, and statutory report templates come from your jurisdiction pack — so when a reviewer asks how something was handled, the answer is a document, not a reconstruction.

Can we start with access requests and add the privacy modules later?

Yes. Every module runs on one shared platform and is enabled through configuration — many small institutions start with FOI request management and switch on assessments, breach management, complaints, and the risk register as the program matures. No migration, no second system, and no change in price: every feature is in every tier.

The Whole Mandate. One Coordinator. Covered.

Try AccessPoint free for 30 days in the Microsoft 365 tenant your organization already has — pre-configured for your statute.

Start Free Trial