Solutions · By role

Case files that live inside your recordkeeping plan, not around it

Records collected from SharePoint, OneDrive, Outlook, and Teams without leaving your tenant, retention set per case type with its own period and start point, dependency-aware disposition — and a purge log that is never itself purged.

Every FOI request is a records event you didn't schedule: copies of official records pulled into working folders, emailed to reviewers, saved to desktops — and then kept forever, because nobody owns their disposition. AccessPoint changes the shape of the problem. Case copies are collected from SharePoint, OneDrive, Outlook, Teams, and OneNote into a governed case workspace inside your own tenant — not exported into a vendor's cloud — and every case type carries a retention rule, so the copies FOI creates finally have a lifecycle of their own.

Retention runs as one engine across five registers — requests, assessments, incidents, complaints, and standalone privacy risks. Each request, assessment, incident, and complaint type carries its own retention period in months and, where more than one date makes sense, its own start point; standalone risks take theirs from their risk category. The default is deliberately conservative: a blank period means keep indefinitely, so nothing ages out until you decide it should. One retention review panel then lists everything that has expired, whatever kind of case it is.

Disposition is where most systems get vague, and where AccessPoint is precise. Cross-case dependencies block a purge server-side — an expired request that an open complaint still contests is listed with its block reason and refused, because destroying it would orphan the other side's evidence trail. Eligibility is re-checked at the moment of purge, the confirmation states exactly how many cases and documents will be destroyed, and every purge lands in a purge log recording what, who, and when — the one record that is never itself purged.

What a records manager needs from an FOI & privacy system

The recordkeeping tests to hold any case system to — most tools fail the disposition half.

Capture from where records live Case records collected directly from SharePoint, OneDrive, Outlook, Teams, and OneNote — including Copilot interaction history — instead of staff exporting copies to desktops and drives.
Copies that stay inside the boundary The case file and its documents belong in your tenant, under your governance stack — not duplicated into a vendor repository outside your recordkeeping plan.
Retention by type, not one global clock Your schedule doesn't treat a breach file like a routine request. Periods and start points should be set per case type, with keep-indefinitely as the safe default.
Dependencies that block destruction An expired case another open case still depends on must be refused disposition by the system — with the reason shown — not caught by someone's memory.
Disposition you can prove A permanent log of every purge — what was destroyed, by whom, when, and how many documents — that survives the records it documents.
A way out that isn't a project Case audit exports for a single file, and a business-readable export of everything on demand — because the database is yours.

How AccessPoint handles the records lifecycle

From capture to defensible destruction, in one governed system.

Capture without the sprawl

Search SharePoint, OneDrive, and Outlook and add records straight to a case — and capture Teams chats, OneNote pages, calendars, and Copilot interaction history the same way. Collection happens in the system, not in staff downloads.

Five registers, one retention service

Requests, assessments, incidents, complaints, and standalone risks all age under one engine, with retention period and start point configured per type — and a blank period meaning keep indefinitely, by design.

Cross-case dependency blocks

An expired request contested by an open complaint, an open request a complaint depends on, or a live attached risk blocks disposition server-side, listed with its block reason. Some records are excluded by construction — an assessment In Effect or an Accepted risk is never offered for purge.

A purge that means it

Multi-select across case types with a running total of documents to be destroyed, a confirmation that states the exact counts behind a severe-warning banner, and eligibility re-checked at the moment of purge — a case reopened after listing cannot slip through.

The purge log that outlives the purge

Every disposition is recorded — case type, record, who purged it, when, and the document count. The purge log is the only surviving evidence the record existed, and it is never itself purged.

Disposition on your radar

Retention review carries a live count of closed and purge-eligible cases and pins to My Day as a purpose-built tile — eligible cases, documents at stake, dependency holds, and how long the oldest item has waited.

The disposition difference

Destruction you can stand behind

Applying a retention schedule is easy to claim and hard to prove. AccessPoint makes the proof a by-product of the process.

Excluded by construction Standing records can't age out by accident: an assessment In Effect is the live privacy record for its program, an Accepted risk is a live posture with a sign-off — the engine never offers either.
Checked at the moment it matters Eligibility is verified again at purge time, not just when the list was drawn, and blocked cases are refused server-side with the reason on screen.
Evidence on both sides While a case lives, a hash-chained audit ledger records every action on it, exportable as a court-ready case audit export. Once it's destroyed, the permanent purge log documents the disposition.

Records & Information Managers Questions

How do I stop FOI request copies spreading outside our recordkeeping plan?

By collecting them into a governed case file instead of into downloads. AccessPoint pulls responsive records straight from SharePoint, OneDrive, Outlook, Teams, and OneNote into the case workspace inside your own tenant — custodians upload to the case, reviewers work in the case, and correspondence lives on the case. The copies FOI creates end up in one governed location with a retention rule attached, rather than in whichever folders the review happened to touch.

Can retention periods differ by case type?

Yes — that's the design. Each request type, assessment type, incident type, and complaint type carries its own retention period in months and, where more than one date makes sense, its own retention start point; standalone risks take their period from their risk category. A blank period means keep indefinitely, and that's the default: a tenant that never configures retention never purges anything.

How do I prove a record was destroyed under our schedule?

With the purge log. Every disposition records the case type, the record, who purged it, when, and how many documents were destroyed — and the log is never itself purged, so it remains the permanent evidence of what existed and how it was disposed of. Up to the moment of destruction, the case's hash-chained audit ledger separately documents everything that happened to it, exportable as a court-ready case audit export.

What stops a case being purged while an appeal or complaint is still open?

The system does, server-side. Cross-case dependencies block disposition: a request an open complaint contests, an open request a complaint depends on, or a live attached risk each appear in the eligible list with a block reason and are refused if selected. Eligibility is also re-checked at the moment of purge, so a case reopened between listing and confirming cannot slip through.

Does AccessPoint copy our SharePoint records into a vendor system?

No vendor system is involved. The case workspace, its documents, and the database all live in your own Azure and Microsoft 365 tenant, deployed into your subscription — the publisher has no runtime access. Case copies exist where your governance stack can see them, and when a case is purged its documents and storage are permanently removed with it.

Can we get everything out if we ever need to?

Yes, at two levels. Any single case produces a court-ready case audit export. And because the database is yours, a business-readable export of everything — cases, registers, and history — is always one click away in the Data import and export panel. There is no lock-in to engineer around.

Retention That Actually Disposes.

Try AccessPoint free for 30 days in your own Microsoft 365 tenant — capture, retention, and defensible destruction in one system.

Start Free Trial