A letter that arrives mid-dispute
An employee in a grievance with one of your clients sends a subject access request. The client forwards it to you in a panic. You know what happens next: somebody has to find every email, chat message and document that mentions the employee, across a dozen managers' mailboxes and years of shared drive folders. Then every item has to be read, third party details considered and a release set produced.
Small clients have no tooling for this. Their Microsoft 365 search returns thousands of results, many of them the same thread in five mailboxes.
Why these requests are so heavy
- The data is spread across mailboxes, Teams, SharePoint, HR systems and sometimes WhatsApp on work phones.
- Searches return large volumes of duplicates, because email threads are copied into every recipient's mailbox.
- Every item needs a person to read it and decide what to release, which is slow for a large set.
- Redaction is done by drawing boxes in PDFs, one item at a time.
- Progress is tracked in a spreadsheet, if at all, while a deadline runs.
What it is costing
Consultant and client time running into days, often in the middle of an already difficult case. The risk of releasing something that should have been redacted, or missing something that should have been found. Deadline pressure, because searches take longer than expected. And an unpredictable cost that is hard to quote for, which makes the work uncomfortable to take on.
| Step | Usual approach | What we build |
|---|---|---|
| Search | Keyword search mailbox by mailbox | One collection run across authorised sources |
| De-duplicate | Rarely done | Identical items and repeated threads merged |
| Review | Open every file | Queue grouped by thread and source |
| Redact | Draw boxes in PDFs | Suggested redactions to accept or reject |
| Track | Spreadsheet | Progress and deadline on one screen |
How we build the request workflow
- The client authorises access to the sources to be searched. For Microsoft 365 this uses its own search and export tools with the client's administrator approval, rather than logging into individual mailboxes.
- Search terms, such as names, nicknames, email addresses and employee numbers, and the date range are recorded as part of the request file.
- Collected items are de-duplicated and email threads are grouped, so a reviewer reads each conversation once.
- A model flags personal details of other people, such as names and contact details of colleagues, as suggested redactions. The reviewer accepts, rejects or adds to each one.
- Reviewers mark each item as release, release redacted or withhold, with a reason chosen from options your advisers define.
- The release set is produced as indexed PDFs with redactions applied permanently, and a log records every decision.
- A dashboard shows items remaining, reviewer progress and days left against the deadline you enter.
What must be released, what can be withheld and what the deadline is are legal questions for your advisers or the client's. The workflow organises and records the review. It does not make those decisions.
What this changes
The request file also becomes a record in its own right: which sources were searched, with which terms, over which dates, and what was decided about each item. If the employee later questions how the search was done, that record answers them without anyone relying on memory.
The volume of material a reviewer faces shrinks once duplicates are removed. Review is a steady queue rather than an overwhelming folder. Redactions are consistent and applied properly, not just covered by a black box someone could remove. Progress is visible, so there are no last-minute surprises. And your consultancy can quote for this work with more confidence, because the process is predictable.
Is this familiar?
- Clients forward access requests to you with no idea where to start.
- Searching means going through mailboxes one at a time.
- Reviewers read the same email thread several times.
- Redaction is done by hand in PDFs.
- You track progress against the deadline in a spreadsheet.