Module 04 — The Final Approver

Managers and delegated decision-makers with the authority to authorise release · 30–40 minutes · Prerequisites: Module 00 — Foundation and Module 02 — The Reviewer (Module 03 recommended, as your review of documents builds on the senior-tier checks)

In a hurry? Jump to the quick-reference card or the knowledge check — or print the all-roles reference.

Learning objectives

By the end of this module you can:

  1. Describe your org-wide scope and where your work appears (“Approvals”).
  2. Give per-document final approval (“Final Approval”“Confirm Approval”) and explain the freeze it causes.
  3. Use “Sign Off Selected” safely, understanding that it freezes every selected document at once.
  4. Complete the case-level attestation on “Finalise & Close”: choose the “Disclosure outcome” and press “Attest case complete”.
  5. State your export-package rights and apply the fail-closed release discipline: verify before release, never bypass a blocked export.

1. Scope and navigation

The Final Approver is organisation-wide — you see every case, across every department, so you can approve across teams. This is fixed for the role and cannot be narrowed.

In the navigation rail, a Final Approver’s rail item reads “Approvals” instead of “My Queue” — a label change only: it opens the same queue page (still headed “My Queue”) listing documents in active review across every department. The documents actually awaiting your final sign-off appear on “Home”, under “Approval queue — by deadline risk”.

Everything from the reviewer tier still applies: you can review, decide detections, assign grounds, and (like the senior tier) send work back with “Request Changes”“Send Back”. What is unique to your tier — shared only with the Lead — is the final sign-off itself, the case attestation, and the “Ombudsman Package”.

Tip — independent approval: By default Veil will not let someone sign off a document whose redactions they personally reviewed or changed — the reviewer and the approver should be two different people. An Administrator or the Lead can relax this for a very small team; when it is off, Veil records a clear “self-approved” marker on the approval for later audit.

2. Per-document final approval — and the freeze

Open a document in “Reviewed (Initial)” (until then the toolbar reads “Signed Off — Awaiting Final Approval”), satisfy yourself the decisions and grounds are right, then:

  1. Press “Final Approval”
  2. Confirm with “Confirm Approval”
  3. The document becomes “Signed Off” and is frozen.
⚠ Note: if the document is assigned to someone else, you cannot approve it — even as a Final Approver or Lead; there is no role bypass on assignment. Ask the Lead to reassign it to you (audited) first. Unassigned documents can be approved by any Final Approver or Lead.
⚠ Warning: A frozen (signed-off) document’s redaction set is locked — detections can no longer be changed (“Detections are locked after final approval”). Send the document back for changes before final sign-off if anything is wrong.

Before approving, check for anything that would embarrass the release later: a red “{N} unlocatable” badge, redacted detections without grounds, or [REVIEW REQUIRED] types decided in bulk rather than by hand. Approving is the last human gate before the redactions are burned in.

3. Bulk sign-off — “Sign Off Selected”

On the case’s Documents tab, tick documents (or “Select all documents”) to reveal the bulk-action bar. “Sign Off Selected” gives final sign-off to several reviewed documents together (Final Approver / Lead).

⚠ Warning: “Sign Off Selected” freezes every selected document at once — the same irreversible lock as a single final approval. Confirm each one is correct first; a frozen document’s redactions can no longer be changed.
Tip: Filter with the “Search documents...” box before selecting. Each bulk action authorises every selected document independently, so a selection straying into content you cannot access is rejected as a whole — not silently trimmed. The same reject-whole applies if any selected document is assigned to another person — reassign first, then bulk-act.

4. Case attestation on Finalise & Close

Per-document approval is not the end. At the case level, on the “Finalise & Close” screen, the assigned approver completes the “Final sign-off” panel:

  1. Choose the “Disclosure outcome”“Granted in full”, “Granted in part”, or “Refused”.
  2. Press “Attest case complete”

The attestation is the formal statement that the disclosure decision is made and the case is complete. It matters mechanically too: generating an external package (Requester or Ombudsman) requires the case to be fully attested (and the agency name to be set) — without it, the export is blocked with an explanatory message.

The Finalise & Close screen with the three package cards (Requester / Internal / Ombudsman) and the “Generate Export Package” button
The Finalise & Close screen — three package cards and “Generate Export Package” (shown on a council-branded demo instance)

After attestation, the Lead handles the terminal steps: “Mark as released” under “Release for disclosure” (which freezes the case and all its documents and stamps the disclosure date), then “Close & archive”.

5. Your export-package rights

The Final Approver can produce all three packages:

The “Select Export Package” cards with the per-package “Includes” lists
The “Select Export Package” cards with their per-package “Includes” lists (shown on a council-branded demo instance)
⚠ Warning: The Ombudsman package contains the original, unredacted documents. Never send the Ombudsman or Internal package to a requester — only the Requester package is screened for external release. Withheld content can escape through more than the PDFs: schedules, filenames, previews, and reports are all leak channels, and only the Requester package screens them (withheld-text column and reviewer reasoning omitted, filenames anonymised, verification report excluded).

6. Responsibility framing — verify before release

Your sign-off carries the release. Three disciplines:

Verify before release. During export you will see “Verifying redactions are permanent...”. Check “Document Readiness” first — only “Signed off — ready to export” documents export cleanly; readiness badges also flag “Not Signed Off”, “Missing Grounds”, and “Review Incomplete”. When the package generates, a SHA-256 integrity hash is shown and it appears in “Export History”.

The system fails closed — respect it.

⚠ Warning: Veil fail-closes. An external release (Requester or Ombudsman package) is blocked if the automated check finds a leak or cannot run. “Couldn’t verify” is not “clean”.

Never bypass a block. Do not override or work around a blocked export to force a release, and do not “release” by any route other than a verified “Requester Package”. Redaction at export is permanent — the withheld text is destroyed, not hidden — but that guarantee only holds for a package that passed verification. If a document cannot be verified clean, the answer is to fix it, not to ship it.

Under LGOIMA the covering letter’s right-of-review notice cites s 27(3), and withholding is grounded in s 6 / s 7 / s 17. Under OIA the right-of-review notice cites s 28(3), and withholding is grounded in s 6 / s 9 / s 18.

Hands-on exercise

On the demo instance, using a case whose documents are in “Reviewed (Initial)”:

  1. On “Home”, find “Approval queue — by deadline risk” and confirm it lists work awaiting your sign-off across departments (org-wide scope). Note that the rail’s “Approvals” item opens the shared queue page of documents in active review.
  2. Open one document, audit its decisions, then press “Final Approval”“Confirm Approval”. Confirm the badge reads “Signed Off” and try to change a detection — observe that detections are locked.
  3. On the Documents tab, select the two remaining reviewed documents and use “Sign Off Selected”, having checked each first.
  4. On “Finalise & Close”, review “Document Readiness”, then complete the “Final sign-off” panel: choose “Granted in part” as the “Disclosure outcome” and press “Attest case complete”.
  5. Select the documents, choose “Requester Package”, and press “Generate Export Package”. Watch “Verifying redactions are permanent...”, then “Download Package” and note the SHA-256 in “Export History”.
  6. Ask your trainer to load the prepared “leaky” case; attempt an external export and observe the “Export Failed” card. Identify the flagged document and explain — without doing it — what would be needed before this case could release.
  7. Generate an “Ombudsman Package” on the clean case and state, to your trainer, who is allowed to receive it.

Knowledge check

Quick-reference card

TaskWhere / label
Your work queue“Home”“Approval queue — by deadline risk”; the rail’s “Approvals” item (relabelled “My Queue”) opens the shared active-review queue — org-wide scope
Approve one document“Final Approval”“Confirm Approval”“Signed Off” (frozen; “Detections are locked after final approval”)
Approve severalDocuments tab → “Sign Off Selected” — freezes all selected at once; check each first
Wrong before approval?“Request Changes”“Send Back” (returns to “In Review”) — impossible after the freeze
Case attestation“Finalise & Close”“Final sign-off”“Disclosure outcome” (“Granted in full” / “Granted in part” / “Refused”) → “Attest case complete”
Export gateExternal packages need full attestation + agency name set
Your package rights“Requester Package”, “Internal Package”, “Ombudsman Package” (unredacted originals — never external)
Readiness badges“Signed Off”, “Not Signed Off”, “Missing Grounds”, “Review Incomplete”
Verification“Verifying redactions are permanent...”; statuses “PASSED” / “LEAK-FOUND” / “UNVERIFIED” / “EXCEPTION” (+ “WITHHELD IN FULL”, not a failure)
Blocked export“Export Failed” — fix flagged documents and regenerate; never bypass the block
← Module 03 — The Senior Reviewer Your role’s path may skip ahead — see Start Here Module 05 — The Administrator →