Demo · Bounded Staff Hub participation

Give staff a bounded route to compliance —
without making every participant an operator.

This demo illustrates a per-tenant URL pattern — regalign.app/intake/your-firm — for bounded staff participation. The landing surface can be opened without an operator sign-in; channel-specific verification, authorisation, routing and confidentiality controls vary by workflow and remain subject to controlled runtime assurance before production reliance.

200
Illustrative staff population
5
Illustrative operator seats
0
Illustrative extra operator seats for intake

This illustrates the intended participation model: operator seats are for people who administer and triage, while staff can use bounded intake routes without becoming full operators. Actual seat treatment, limits and commercial terms are contractual and must be confirmed for the relevant engagement.

01

Five intake patterns on one URL

/intake/saltireSandbox · public landing
  • Speak up confidentially
    Audience: Staff, contractors or third parties, subject to configured intake scope
    Auth: Anonymous/named intake pattern with one-time lookup token where configured
    Routed to: Designated investigator role pattern
  • Internal SAR
    Audience: Staff within the configured tenant scope
    Auth: Work-email link pattern; token controls remain subject to runtime assurance
    Routed to: MLRO / Deputy MLRO role pattern
  • Ask compliance
    Audience: Staff within the configured tenant scope
    Auth: Work-email verification pattern
    Routed to: Compliance Officer / MLCO triage pattern
  • Report a breach or incident
    Audience: Staff within the configured tenant scope
    Auth: Work-email verification pattern
    Routed to: Compliance breach / incident triage pattern
  • DSAR (data subject request)
    Audience: Data subjects within the configured intake scope
    Auth: Open-intake pattern; identity handling remains case-dependent
    Routed to: DPO / Deputy DPO workflow pattern; statutory timing remains case-dependent

Why this matters: The design is intended to route each channel to a designated role under configured confidentiality rules. Production reliance on that separation depends on exercised token, RLS and runtime evidence; the demo itself is not proof of those controls.

02

Illustrative journey: staff submits → operator triages

/intake/saltire/ask/submitDemo staff side
Your work email
alex.morgan@saltire.je
Topic
Gifts & hospitality
Your question
A counterparty offered tickets to a sports event. Threshold? Need pre-clearance?
Demo verification-link step before the question is presented for triage.
/compliance-queriesDemo operator side
From alex.morgan@saltire.je· illustrative
Gifts & hospitality

A counterparty offered tickets to a sports event. Threshold? Need pre-clearance?

Why this matters: This demonstrates the intended closed-loop triage pattern. It does not by itself establish production authentication, delivery, audit-provenance or confidentiality effectiveness.

03

Per-tenant URL pattern for staff communications

/_authenticated/admin/intake-linksTenant-admin demo
Staff Hubregalign.app/intake/saltireCopy
Speak-upregalign.app/speak-up/submitCopy
Internal SARregalign.app/intake/saltire/sar/submitCopy
Ask complianceregalign.app/intake/saltire/ask/submitCopy
Report a breachregalign.app/intake/saltire/breach/submitCopy
DSARregalign.app/intake/saltire/dsar/submitCopy

The demo shows configured work-email domains and shareable route patterns. Before live use, each route's verification, token, access-control and confidentiality behaviour must be accepted against the relevant runtime evidence.

Why this matters: A firm can choose where to publish approved intake links — for example on an intranet, staff portal or policy material — once the relevant channel has been configured and accepted for live use.

Illustrative role-routing pattern
Compliance Officer / MLCO

The demo shows staff questions and breach reports being presented for compliance triage. Actual allocation and permissions are tenant-configured and require runtime evidence.

MLRO

The internal-SAR design uses a separately routed workflow intended to support restricted handling. The demo does not assert that production isolation or tipping-off controls have been fully exercised across every route.

DPO

The DSAR design supports intake and case handling. Statutory deadlines, identity checks, extensions and evidence requirements remain case-specific and operator-controlled.

Try the sandbox participation pattern

The sandbox Staff Hub route is available at /intake/saltire. The landing surface does not require an operator sign-in; channel-specific checks and production controls vary by workflow and are not proven merely by opening this demo.

Ready when you are

Seen enough to talk?

Every demo on RegAlign is open — no form wall, no sales chase. When you're ready, request pilot access and we'll book a working session.