Solutions · By organization

Run your clients' privacy and FOI programs — your tenant or theirs

For consultancies offering privacy and FOI as a managed service: host AccessPoint once and serve every client from your own tenant, or work inside a client's own tenant on the licence they hold when their governance calls for it. Annual pricing is tiered by organization size, and every tier carries every feature and unlimited usage — so the tool never meters what your practice does.

A growing share of public-sector privacy work is delivered by consultants: small municipalities, agencies, boards, school boards, and health units that can't staff a full-time FOI coordinator or privacy officer retain a firm to run the program for them — a fractional privacy office. Firms run that model in two shapes, and AccessPoint is built to support both rather than force a choice.

The first shape is hosting it yourself. Deploy AccessPoint once, in your own Microsoft 365 and Azure tenant, and process every client's requests, assessments, incidents, and complaints there. A custom Customer field tags each case with the client it belongs to; saved dashboard views filter every register to one client in a click; and statutory reports and Report Studio dashboards slice by customer — so each client gets clean, client-specific reporting, exported and sent with your invoice or reviewed live by their people connecting as guests. Pricing stays predictable while you do it: annual tiers are set by organization size, and every tier carries every feature and unlimited usage, so the volume your practice processes never changes the bill.

The second shape is operating in the client's tenant. The client licenses AccessPoint themselves — the published flat rate, billed on their own Microsoft invoice — and your team connects to their environment and runs the program there. That's the right fit when a client's counsel or IT wants the records inside their own boundary, and it makes offboarding trivially clean: if the engagement ever ends, the platform, the history, and the audit trail of your work stay with them. Both shapes run the same platform, so your methodology, templates, and training carry across every engagement.

What a managed-service practice needs from its platform

Running multiple client programs is its own discipline. These are the properties that make a practice scale — whichever tenant the work lives in.

Both custody models, one platform Host clients in your tenant, or work inside theirs — chosen per engagement, with the same workflows, templates, and playbook either way.
A caseload that organizes by client A custom Customer field tags every request and assessment, saved dashboard views filter each register to one client, and a case-matched role scoped to that same field bounds what each client's own people can see. Twelve clients shouldn't feel like twelve systems.
Client-ready reporting Statutory reports and Report Studio dashboards sliced per customer and exported cleanly — the recurring deliverable that shows what the retainer bought.
Economics that don't scale with seats Tiers are set by organization size, not by what you process — every tier carries every feature and unlimited usage, so a busy month never turns into a licence line item.
Onboarding measured in days A new client is a jurisdiction pack plus a guided history import — into your tenant or theirs — not a quarter-long implementation.
Work you can prove Every action your team takes lands on a hash-chained audit ledger, with court-ready case audit exports as client deliverables.

How the practice runs on AccessPoint

One platform, two hosting shapes — these are the pieces that carry a multi-client caseload.

One tenant, many clients

Host AccessPoint in your own Microsoft 365 and Azure tenant and process every engagement there — requests, PIAs, breaches, complaints — with your clients' people added to their own cases as readers and advisors, seeing exactly the files you add them to.

The Customer field

Add a custom Customer field to requests, assessments, and cases; saved dashboard views filter the caseload per client, and reports slice by customer — client-specific status is a click, not an assembly job.

Case-matched roles, one per client

Build a role whose permissions apply only to cases matching a rule — "Customer is Acme" — and that client's people see exactly their own cases and nothing else, automatically, as new cases arrive. The editor shows how many cases a rule currently matches before you save it.

Reports your retainer can mail

Statutory report templates and Report Studio dashboards generate per customer and export cleanly — recurring, client-branded proof of what the engagement delivered.

Or work in their tenant

When a client licenses AccessPoint themselves, your team connects to their environment and runs the program inside their boundary — their data stays theirs, and offboarding is just deprovisioning your access.

Client onboarding via guided import

The Data import & export panel brings a new client's history in from their legacy system or spreadsheet — validated per row, legacy case numbers preserved, documents staged with optional hash verification.

Statute-aware across your client base

Jurisdiction packs cover 106 regimes, and every case carries its own legal authority — so one practice serves MFIPPA municipalities, FIPPA institutions, and federal clients with the right clocks and exemption catalogues on each file.

Two shapes, one practice

Host it, or embed in theirs — choose per client

Some clients just want their FOI answered — host them in your tenant and hand them clean reports. Others need records inside their own boundary — run their license in their tenant. It's the same platform either way, so your methodology carries across every engagement.

MSP-hosted One deployment in your own tenant, clients added to their own cases as readers and advisors, and the Customer field keeping every client's work organized and reportable.
Client-hosted The client's license, their tenant, their audit ledger — your team operates inside it with access they grant and revoke.
Movable between the two Export mirrors import, so a hosted client can graduate to their own tenant — history, legacy numbers, and documents included — without starting over.

Onboarding a new managed-service client

From signed engagement to processing their caseload — the practical sequence, in either shape.

  1. Choose the shape for this client: hosted in your tenant for speed and simplicity, or in their tenant when their governance calls for it. Both run the same platform, so nothing about your delivery changes.
  2. Hosted: tag the engagement with your Customer field and set up client-filtered dashboard views and reports. Client-tenant: the client subscribes on the Microsoft commercial marketplace (30-day free trial, flat rate, their own invoice) and deploys the backend from the template — with your guidance or their IT's.
  3. Apply the jurisdiction pack for their regime: deadlines, exemption catalogues, fee rules, letter templates, and statutory report formats arrive configured, ready for your firm's adjustments.
  4. Import their history through Settings → Data import & export: requests, assessments, incidents, complaints, requestors, and documents, validated per row, with legacy case numbers preserved.
  5. Start processing. Your analysts work My Day queues; the client sees exactly what you choose to share — exported client-filtered reports, or live participation as guests.

Privacy & FOI Managed Service Providers Questions

Can a consultant use AccessPoint to process FOI requests and PIAs for multiple clients?

Yes, in either of two shapes. Host AccessPoint in your own tenant and serve every client from one deployment — their people connect as guests, and a custom Customer field keeps caseloads, dashboards, and reports organized per client. Or work inside a client's own tenant, on the licence they hold, when they want records inside their boundary. Pricing is annual and tiered by organization size either way, with every feature and unlimited usage in every tier — and many practices run both shapes at once, chosen client by client.

How does licensing work for a managed-service practice?

Annual, published on the pricing page, tiered by organization size — with every feature and unlimited usage in every tier. If a client hosts, they license AccessPoint for their own tenant at the published rate on their own Microsoft invoice, and your team's access costs nothing additional — nothing to resell, so your revenue stays pure services margin. If you host, the subscription sits with your practice on the same terms. Setting up a practice that serves several clients from one deployment is worth a short conversation so we can get the arrangement right for your shape — contact us and we'll sort it out before you quote.

How do we keep each client's work organized in a hosted tenant?

With two different tools for two different jobs. For organizing and reporting: a custom Customer field tags every request, assessment, and case with the client it belongs to; saved dashboard views filter each register to one client; and statutory reports and Report Studio dashboards slice by customer, exporting cleanly for each client's package. For access: build a **case-matched role** whose rule keys on that same Customer field — "Customer is Acme" — and its permissions apply only to matching cases. Everything else stays invisible, new cases join automatically as they arrive, and the editor tells you how many cases a rule currently matches before you save it. For one-off involvement you can instead add someone to a single case as a reader or advisor. One caveat worth knowing: case-matched rules only ever *add* access, so a client contact must not also hold a role that shows them everything.

What does the client actually see?

Whatever you choose to share, at two levels. At minimum: recurring client-filtered reporting — statutory reports and Report Studio dashboards for their program, exported and sent. Beyond that, give the client a case-matched role scoped to their own Customer value and their people work directly in their own caseload — every case theirs, none of anyone else's, with new ones appearing automatically. Add the "Build reports on matching cases" permission and they get the report builder, saved reports and Ask AccessPoint over only their cases, with requestor PII fields never offered and their saved reports kept separate from your team's. For someone who only needs one file, adding them to a single case as a reader or advisor is the lighter option.

When should a client run AccessPoint in their own tenant instead?

When their counsel or IT wants the records inside the client's own boundary, when their compliance posture makes tenancy the clean answer, or when they may eventually take the program in-house. In that shape they license AccessPoint at the published flat rate, your team operates it with access they grant and revoke, and everything your firm builds — case history, audit trail, configuration — stays with them if the engagement ends. That clean-exit story tends to help you win the engagement in the first place.

Can a hosted client later move to their own tenant?

Yes — that's a designed path, not a rescue. The Export tab produces the same business-readable workbook the importer accepts, so you can trim an export to the client's records and import their caseload into a tenant they license — with per-row validation, legacy case numbers preserved, and documents staged through storage on the way. Practices use exactly this to graduate a growing client from the hosted shape to their own deployment without re-keying history.

Your Practice. Either Tenant. One Platform.

Book a demo and we'll walk through both hosting shapes — and how the Customer field keeps a multi-client caseload sane.

Request a Demo