Give staff a bounded route to compliance —
without making every participant an operator.
This demo illustrates a per-tenant URL pattern — regalign.app/intake/your-firm — for bounded staff participation. The landing surface can be opened without an operator sign-in; channel-specific verification, authorisation, routing and confidentiality controls vary by workflow and remain subject to controlled runtime assurance before production reliance.
This illustrates the intended participation model: operator seats are for people who administer and triage, while staff can use bounded intake routes without becoming full operators. Actual seat treatment, limits and commercial terms are contractual and must be confirmed for the relevant engagement.
Five intake patterns on one URL
- Speak up confidentiallyAudience: Staff, contractors or third parties, subject to configured intake scopeAuth: Anonymous/named intake pattern with one-time lookup token where configuredRouted to: Designated investigator role pattern
- Internal SARAudience: Staff within the configured tenant scopeAuth: Work-email link pattern; token controls remain subject to runtime assuranceRouted to: MLRO / Deputy MLRO role pattern
- Ask complianceAudience: Staff within the configured tenant scopeAuth: Work-email verification patternRouted to: Compliance Officer / MLCO triage pattern
- Report a breach or incidentAudience: Staff within the configured tenant scopeAuth: Work-email verification patternRouted to: Compliance breach / incident triage pattern
- DSAR (data subject request)Audience: Data subjects within the configured intake scopeAuth: Open-intake pattern; identity handling remains case-dependentRouted to: DPO / Deputy DPO workflow pattern; statutory timing remains case-dependent
Why this matters: The design is intended to route each channel to a designated role under configured confidentiality rules. Production reliance on that separation depends on exercised token, RLS and runtime evidence; the demo itself is not proof of those controls.
Illustrative journey: staff submits → operator triages
A counterparty offered tickets to a sports event. Threshold? Need pre-clearance?
Why this matters: This demonstrates the intended closed-loop triage pattern. It does not by itself establish production authentication, delivery, audit-provenance or confidentiality effectiveness.
Per-tenant URL pattern for staff communications
regalign.app/intake/saltireCopyregalign.app/speak-up/submitCopyregalign.app/intake/saltire/sar/submitCopyregalign.app/intake/saltire/ask/submitCopyregalign.app/intake/saltire/breach/submitCopyregalign.app/intake/saltire/dsar/submitCopyThe demo shows configured work-email domains and shareable route patterns. Before live use, each route's verification, token, access-control and confidentiality behaviour must be accepted against the relevant runtime evidence.
Why this matters: A firm can choose where to publish approved intake links — for example on an intranet, staff portal or policy material — once the relevant channel has been configured and accepted for live use.
The demo shows staff questions and breach reports being presented for compliance triage. Actual allocation and permissions are tenant-configured and require runtime evidence.
The internal-SAR design uses a separately routed workflow intended to support restricted handling. The demo does not assert that production isolation or tipping-off controls have been fully exercised across every route.
The DSAR design supports intake and case handling. Statutory deadlines, identity checks, extensions and evidence requirements remain case-specific and operator-controlled.
Try the sandbox participation pattern
The sandbox Staff Hub route is available at /intake/saltire. The landing surface does not require an operator sign-in; channel-specific checks and production controls vary by workflow and are not proven merely by opening this demo.