Get started

Set up your organisation

Create your organisation in DSAR Respond, invite your team, and assign the Admin, Member, and Viewer roles.

What this task achieves

Setting up your organisation gives DSAR Respond three things it needs before any request can be handled: your organisation's name, the colleagues who will work on cases, and the role each of them holds. The name is not cosmetic — it appears on your request portal and on communications sent to the people who make requests, so use the name they would recognise.

Before you begin

You need the Admin role. If you created your organisation's account, you already have it. The work happens in the setup wizard the first time you sign in, or afterwards in Settings, where the Team tab is visible only to Admins. Have the email addresses of the colleagues you want to invite to hand, and decide in advance what each of them should be able to do.

Complete the setup wizard

Your organisation is created for you when you first sign up, with a default name derived from your email address. The first time you sign in — after verifying your email address — DSAR Respond opens a four-step wizard so you can replace that default and bring your team in.

  1. On Step 1 of 4, Name your organisation, type your organisation's name in Organisation name. It must be between 2 and 100 characters.
  2. Check the portal address shown underneath. DSAR Respond derives it from the name you type and checks whether it is available; if it is already taken, the page says so and offers an alternative to try. Change the name until you have an address you are happy with, because this is the address your requesters will use.
  3. Select Save & Continue.
  4. On Step 2 of 4, Invite your team, add the email addresses of colleagues who should have access. Three rows are shown; use + Add another for more, up to the limit set by your plan. See Understand the roles below before you decide who to add here.
  5. Select Next. Invitations are sent immediately, and the final step reports how many went out.
  6. Step 3 of 4 is Connect Microsoft 365, covered in Connect Microsoft 365. You can complete it later.
  7. Step 4 of 4, You're all set, summarises what you configured. Select Go to Dashboard to finish.

Every step except the last has Skip this step, and Back returns to the previous one. Skipping is safe: anything you skip can be done later from Settings.

Invitations sent from the wizard are Viewers

Colleagues invited on Step 2 of 4 are all invited as Viewer, the read-only role. That is deliberate: it is the safest default. If someone needs to work on cases, invite them from SettingsTeam instead, where you choose the role, or change their role there after they accept.

While setup is unfinished, the Dashboard shows a Finish setting up card covering naming your organisation, inviting your team, and connecting Microsoft 365, with a progress indicator and a link into each. It disappears once your organisation has been renamed and at least one invitation has been sent, or once you finish the wizard.

Understand the roles

DSAR Respond has three roles. Choose the least access each person actually needs — you can change a role at any time.

RoleWhat it allows
AdminEverything a Member can do, plus managing the team, managing connectors in Integrations, deleting cases, extending a case deadline, and finalising a case review. Admins also see the Billing, Team, and Connectors tabs in Settings.
MemberRead and work on cases: create and update cases, run discovery, add and organise documents, and prepare responses. Members see the Integrations page and a connector's health, but cannot add, test, or disconnect one.
ViewerRead cases only — no creating or changing a case, running discovery, managing documents, or redacting. The Integrations page is not shown to Viewers.

A missing or greyed-out button is far more often a role than a fault — that check heads the list in Troubleshoot the core workflow.

UK GDPR context

Cases in DSAR Respond hold personal data about identifiable people, and often about third parties who never asked to be involved. You are required to have appropriate security around that data, and limiting who can see it is one of the most effective controls available to you. Give people the narrowest role that lets them do their job, review the list when someone changes team, and remove access promptly when they leave. Record why a particular person needs a broader role if you grant one.

This is operational guidance for UK organisations, not legal advice.

Invite colleagues from Settings

Use this route whenever you need to choose the role, or to invite someone after setup.

  1. Open Settings, then the Team tab.
  2. Select Invite Member. The Invite Team Member dialog opens.
  3. Enter the person's work address in Email address.
  4. Choose Admin, Member, or Viewer in Role. The dialog will not submit until both fields are set.
  5. Select Send Invitation. DSAR Respond confirms that the invitation was sent, and the address appears under Pending Invitations.

If your plan's seat limit is already reached, the invitation is refused and a banner explains the limit rather than sending anything.

Manage members and pending invitations

The Team tab shows everyone in your organisation under Team Members, with their name, email address, role, and the date they joined.

  • Change someone's role. Select a new value in the Role column. The change takes effect immediately.
  • Remove someone. Open the actions menu at the end of their row and select Remove member, then confirm in Remove Team Member. Removal is immediate and they lose access to all cases and data.
  • You cannot change your own role or remove yourself. Your own row shows your role as a plain badge and its actions menu is disabled. Ask another Admin if you need your access changed.

Under Pending Invitations each outstanding invitation shows the address, the date it was sent, the role it grants, and whether it is Pending or Expired.

  • Resend sends the invitation email again to a pending invitation.
  • Cancel withdraws a pending invitation so its link stops working.
  • Neither action is available on an expired invitation. Send a new invitation instead.

Removing a member does not tidy up their work

Removing someone ends their access at once, but it does not reassign the cases they were working on. Before you remove an Admin in particular, make sure another Admin remains — connector management, role changes, deadline extensions, and finalising a case review all need one.

What your colleagues do next

An invited colleague receives an email with a personal link. Opening it shows You've been invited, naming you and your organisation. The Invited email field is fixed to the address you invited; they choose a password of at least eight characters, confirm it, select Create account, and land in your organisation.

Tell them three things in advance, because each explains a failure they might otherwise report to you:

  • The link expires after 7 days and can only be used once. If it has expired or been used, send a new invitation.
  • They must use the mailbox you invited. Signing in with a different address is refused as a mismatch.
  • Someone who already belongs to another organisation in DSAR Respond cannot join yours until they leave that one.

Ask new colleagues to open SettingsAccount and set their First Name and Last Name under Profile Information. An invitation derives a placeholder name from the email address, so until they do this the team list and case history show something unhelpful.

Set your display timezone

Every date and time in DSAR Respond — including case due dates and urgency badges — is displayed in the timezone set on your own account, so get it right before you start work.

  1. Open Settings, then the Preferences tab.
  2. Under Display Preferences, choose your Timezone. UK users should select London (GMT/BST).
  3. Select Save Preferences.

The same tab controls which notifications you receive; Deadline Reminders and Connector Health are the two worth leaving on for anyone who handles cases. Passwords and two-factor authentication are not set here — the Security tab explains that both are managed by your identity provider.

Official sources

What happens next

What happens next

Continue to Connect Microsoft 365 so DSAR Respond can search your organisation's data. If you are not connecting Microsoft 365 yet, go straight to the access-request lifecycle overview — cases can be worked with documents added by hand.

Last reviewed . UK regulatory context.

Previous
About this guidance