Documentation

Reviewing a case

What each part of the review screen does: the two views, what the colours mean, acting on detections, saving your place, and the attestation that closes a case.

The two views

Processing produces detections. Review is where a person confirms them, and nothing leaves SafeRedact without passing through this screen and the sign-off at the end of it. Review offers two ways through the same detections.

By file shows one document at a time in a split pane: the document text on one side, its detections on the other. Selecting a detection highlights it in the text. This view is for reading context: whether “the property manager” three lines up makes a name identifiable, whether a sentence about the requester also contains a third party.

By entity groups every detection of the same value across the whole case: one entry for a person’s name wherever it appears, with a count. This view is for consistency: deciding once that a name is redacted everywhere, rather than meeting it four hundred separate times. Applying a decision at the entity level records it on every instance, and the audit trail notes that the decision was applied as a cascade.

Most reviews use both: entity view to clear the high-volume repeated identifiers, file view to read the documents where judgment is needed.

What the colours mean

Detections carry one of two intents, shown consistently across both views.

  • Redact (marked in the redaction colour): third-party personal data. This will be removed from the disclosed documents.
  • Preserve (marked separately): the data subject’s own information. A DSAR discloses the requester’s data to the requester, so their identifiers are deliberately kept visible. These appear in review so you can verify the pipeline classified them correctly in both directions.

If the subject’s name appears inside a sentence about someone else, that is exactly the case the split pane exists for. Read it and decide.

Acting on a detection

Each detection can be approved as-is, switched between redact and preserve, or dismissed as a false positive. You can also add a detection manually by selecting text in the document pane, for anything the pipeline missed. Every action is recorded with who did it and when, and manual additions are marked as reviewer-added in the audit trail.

Low-confidence detections are surfaced rather than hidden: the confidence dashboard summarises each file’s detection count and confidence range, and flags files with no detections at all, which deserve a manual glance precisely because silence can mean a scanned image rather than a clean document.

Approve all marks every detection in the case approved in one action. It exists for the end of a review, after the entity-level and file-level work is done, not instead of it.

Saving and coming back

Review decisions are saved as you work, in the browser’s own storage on the machine running the case. Closing the tab and returning later resumes where you left off, under the same case name with the same files attached. The same mechanism restores a case after a crash or a forced restart. Decisions survive; nothing needs redoing.

One case runs in one person’s browser. If a case needs more than one reviewer, split it by custodian at case creation, so each custodian’s documents form a separately reviewable case.

Sign-off

Export begins with an attestation step: a named confirmation that the review was performed and the output is approved for disclosure. If any files were never opened or carry unreviewed detections, the screen says so before you attest, and proceeding at that point is an explicit choice that gets recorded rather than a silent default.

The attestation, along with the full decision history, appears in the export pack, described in The export pack.