Module 01 — The Lead
Disclosure leads: official information / privacy officers, coordinators, governance and legal leads accountable for the agency’s disclosure obligations · 90 minutes (60 minutes content, 30 minutes hands-on exercise) · prerequisite: Module 00 — Foundation (roles, the disclosure lifecycle, detections and decisions)
(This module calls the role “the Lead”.)
In a hurry? Jump to the quick-reference card or the knowledge check — or print the all-roles reference.
Learning objectives
By the end of this module you will be able to:
- Create a request on “Log a new request” and explain which fields Veil assigns automatically.
- Upload documents on “Document Ingestion” and read the processing indicators correctly.
- Configure the case workflow on “Review Workflow Setup” and assign documents with “Assign Reviewer”.
- Use the bulk-actions bar safely, respecting its role gating.
- Formally extend a statutory deadline with an audit-trailed reason.
- Create and manage “Custom Rules”, and explain why they are detection rules, not redaction rules.
- Monitor case health from the dashboard, the workflow strip, the Schedule and Audit Trail tabs, and “Reports”.
- Release, close, reopen, or early-close a case — and explain why release is terminal.
1. The Lead’s place in the workflow
The Lead owns requests from start to finish: creating cases, assigning work, setting and extending deadlines, and configuring the workflow. The Lead can also do everything the reviewing roles can — review, make disclosure decisions, send work back, and give final sign-off — and is the only role that can delete a document or create a case. Visibility is always organisation-wide.
Permissions are enforced by the server, not the screen. Some buttons you cannot use are hidden (for example “Sign Off Selected”); others are visible but will be rejected by the server — the system re-checks your role on every action.
2. Creating a request — “Log a new request”
Reference: creating a request in the feature reference
On New Case (“Log a new request”), you enter the request and Veil does the rest.
- Fill in “Request summary”, “Requester name”, “Requester type”, “Date received”, “Priority”, and “Department(s)”.
- Veil assigns the “Reference” and the “Statutory deadline” automatically — neither can be edited on this form. (You can formally extend the deadline later — see section 7.)
- Press “Create Case”. Veil takes you to “Review Workflow Setup”; from there, open “Document Ingestion” to upload.
3. Uploading documents — “Document Ingestion”
Reference: ingestion in the feature reference · current limitations
On “Document Ingestion” (the case’s upload screen):
- Use “Drag and drop files or folders here”, or click to browse. The dropzone lists the accepted formats (PDF, DOCX, XLSX, PPTX, EML/MSG, TXT).
- Watch the “Processing Progress” and “Processing Queue” cards as each file runs through the pipeline.
- Re-uploading the same file shows a non-blocking amber “Duplicate” warning — the file is still added; remove it yourself if it is a duplicate.
- When processing finishes, press “Continue to Review”.
The “Import from SharePoint” tab appears next to the dropzone and is enabled when your instance is connected to Microsoft 365. On the current release the connected tab shows “SharePoint import — coming soon” — in-app library browsing is on the roadmap — so download the files from SharePoint and upload them directly; they join the same “Processing Queue” and run the same pipeline.
Three format warnings worth repeating to your team: .PST email archives and .ZIP folders are not expanded — a ZIP is rejected at upload; export emails as EML or MSG, or unzip first, and upload the files individually. Standalone image files (PNG, JPG and similar) are rejected at upload with “Unsupported file type — supported: PDF, Word, Excel, PowerPoint, email (.eml/.msg), text.” — scanned material must arrive as a PDF, which is read through OCR as normal. Audio and video files are not screened — they may upload, but in a standard deployment Veil does not transcribe, detect, or redact them; never treat a media file as reviewed.
4. The automated pipeline, at a high level
Each uploaded document is processed automatically:
- Validate and convert the file; extract text (OCR, including for scanned PDFs — a cloud feature your administrator configures).
- Pattern detection — structured NZ personal identifiers (phone, email, IRD, NHI, address, bank account, passport, vehicle/driver) at high confidence. This always runs.
- AI detection (if configured) — names and contextual content such as legal privilege, free-and-frank opinions, and commercial sensitivity, with a suggested ground. If the AI layer is unavailable, the document still completes using pattern detection only — but names and contextual sensitivities are not detected.
- The document moves to “Ready for Review” when done, or “Error” if something failed.
Every detection starts pending — Veil never decides for anyone; nothing is pre-redacted. People make every decision.
5. Configuring the workflow — “Review Workflow Setup”
Reference: workflow setup in the feature reference
The Lead configures who works each stage on “Review Workflow Setup”:
- Stages: “Set-up”, “Collect”, “First-Pass Review”, “Second-Pass Review”, “Final Sign-off”, “Release”, “Close” (plus an internal “AI Processing” stage — not shown on the board). On the board itself, Set-up and AI Processing are hidden; you drag people onto “Collect”, “First-Pass Review”, “Second-Pass Review”, and “Final Sign-off”, while Release and Close appear as automatic markers with no assignments.
- Drag people from the “Reviewers” and “Approvers” palettes, and from the regime-aware Leads palette, onto stages.
- The “Currently with:” / “Awaiting sign-off:” strip shows live progress.
- Press “Save Workflow”.
This screen configures the workflow stages, not who works each document. To assign a document to a person, use “Assign Reviewer” on the case’s Documents tab (next section).
6. Assigning documents and the bulk-actions bar
On the case Documents tab, tick per-row checkboxes (or the “Select all documents” box) to reveal a bulk-action bar. Filter first with the “Search documents...” box if the list is long.
- “Assign Reviewer” — assign the selected documents to one person by email (Lead only).
- “Sign Off Selected” — give final sign-off to several reviewed documents together (Final Approver / Lead).
- “Mark Excluded” — exclude the selected documents from the release.
- “Bulk Review” — open the cross-document “Bulk review” page for the selected documents (covered in the power-user module). It works in three numbered steps: “Auto-accept high-confidence detections” (Lead / Senior Reviewer), “Auto-clear structured PII (emails, phone numbers, IDs)” (Senior Reviewer and above), and “Review by reach”.
- “Set AI context hint” / “Re-run detection” — re-process the selection with extra context.
- “Delete” — permanently remove the selected documents (Lead only).
“Sign Off Selected” freezes every selected document at once — the same irreversible lock as a single final approval. Confirm each one is correct first; a frozen document’s redactions can no longer be changed.
Each bulk action authorises every selected document independently, so a selection straying into a department you cannot access is rejected as a whole — not silently trimmed. The same reject-whole applies on the assignment axis: if any selected document is assigned to another person, the whole selection is rejected — even for the Lead. Reassign it to yourself (or clear the assignment) first, then bulk-act.
7. Extending the statutory deadline
The statutory deadline is assigned automatically at intake, but the Lead can formally extend it when a request genuinely needs more time.
- Press “Extend deadline” on the case’s Details page (Lead only).
- The panel shows the read-only “Current deadline:” and the ceiling as “Max extension: {N} working days”, then asks for a “New deadline” and a mandatory “Reason for extension”.
- The new date cannot exceed your agency’s maximum extension; the reason is required and written to the audit trail.
- An extension moves the existing deadline to the new date — it does not restart the clock. The reason field’s guidance adapts to your regime, because the extension provisions differ between the two Acts.
8. Custom detection rules — “Custom Rules”
Reference: custom rules in the feature reference
“Custom Rules” teaches Veil agency-specific things to look for — “Agency-specific detection rules that run alongside the AI — keywords, patterns and entities mapped to withholding grounds.” The screen is shared between the Lead and the Senior Reviewer.
- “New rule” opens the editor: “Rule name”, “Type” (Keyword / Pattern / Entity / Combination), “Match mode” (Exact / Fuzzy / Regex), “Keywords / pattern”, “Withholding ground”, “Priority”, “Description”.
- Save it off (“Save as Draft”) or turn it on now (“Save & Activate”); the per-row switch flips a rule between Active and Draft. Only Active rules run (“Drafts are saved but never match documents”).
- “Import” / “Export” move whole rule sets in and out as JSON.
- The stat strip tracks “active rules”, “drafts — not yet running”, “matches”, and “grounds covered”.
These are detection rules, not redaction rules — “Rules supplement the AI — they never override a reviewer.” A match becomes an ordinary detection for a person to accept or reject.
9. Monitoring the caseload
- Dashboard (“Home”) — the “Statutory deadline health” panel classifies cases as “On track”, “Urgent”, or “Overdue”, alongside your personal queue.
- “Review Workflow Setup” — the “Currently with:” / “Awaiting sign-off:” strip shows where each case sits.
- “Withholding Schedule” (the Schedule tab) — every withheld item grouped by ground, with an editable “Covering Statement”, the “Right of Review (Standard Text)”, and “Preview as PDF”.
- “Audit Trail” (the Audit tab) — the “Immutable audit log” (“entries cannot be modified or deleted”): every action with its user, role, target, and timestamp; search, filter by type, and “Export CSV” / “Export PDF”.
- “Reports” — statutory reports and disclosure analytics (case roles only): the regime’s Compliance Summary, “Withholding Schedule”, “Chain of Custody”, and “Cost Recovery”, with the “Reporting period” selector for the analytics.
10. Export packages — the Lead can produce all three
Reference: export & verification in the feature reference · FAQ: an export is blocked
Package generation and download are gated by role tier; the Lead is the only role, alongside the Final Approver, that can produce all three:
- “Requester Package” — the only package screened for external release.
- “Internal Package” (marked “Recommended”) — for your own records.
- “Ombudsman Package” — the full disclosure file, including the unredacted originals. Never send it to a requester.
Generating an external package (Requester or Ombudsman) requires the case to be fully attested and your agency name to be set — otherwise the export is blocked with an explanatory message. Veil fail-closes: an external release is blocked if the automated check finds a leak or cannot run.
11. The end of the case — release, close, reopen
The end of the case lives on “Finalise & Close”. The assigned Final Approver completes the “Final sign-off” panel (“Attest case complete”, choosing a “Disclosure outcome”: “Granted in full”, “Granted in part”, or “Refused”). Then the Lead takes over:
- Once attested, press “Mark as released” under “Release for disclosure”. This freezes the case and all its documents and stamps the disclosure date — it is terminal. The case then reads “Released for disclosure”.
- Finally, “Close & archive” the case with a closure outcome; the Lead can “Reopen case” later if needed.
- Administrative early-close outcomes for cases that never reach release: “Withdrawn”, “Transferred”, “No information held”.
Release is irreversible. Be certain the package you have generated and checked is the one you intend to disclose before marking the case released.
Hands-on exercise
Work on the demo instance (demo seed data; upload the sample files provided by your trainer — never real case material).
- Create a case. Open “New Case” and complete “Log a new request”: a short “Request summary”, a fictional “Requester name”, and two departments under “Department(s)”. Before pressing “Create Case”, note the auto-assigned “Reference” and “Statutory deadline”.
- Upload. On “Document Ingestion”, drag in the sample files. Watch “Processing Progress” and the “Processing Queue”. Re-upload one file deliberately and observe the amber “Duplicate” warning; remove the duplicate. Press “Continue to Review”.
- Configure the workflow. Open “Review Workflow Setup”. Drag one person from “Reviewers” onto “First-Pass Review” and a Final Approver from “Approvers” onto “Final Sign-off” (a Senior Reviewer can only be dropped on the review stages). Press “Save Workflow”.
- Assign a document. On the Documents tab, tick two documents and use “Assign Reviewer” to assign them to a demo reviewer.
- Extend the deadline. Press “Extend deadline”, note the “Maximum Extension Date”, set a “New Deadline”, and enter a “Reason for Extension”. Then open the “Audit Trail” tab and find your extension entry.
- Create a rule. On “Custom Rules”, press “New rule”, build a Keyword rule mapped to a withholding ground, and use “Save as Draft”. Confirm the stat strip counts it under “drafts — not yet running”.
- Check case health. Return to “Home” and locate your case in the “Statutory deadline health” panel.
Knowledge check
Quick-reference card
| Task | Where | Label | Gating |
|---|---|---|---|
| Create a request | New Case | “Log a new request” → “Create Case” | Lead only |
| Upload documents | Case upload screen | “Document Ingestion” → “Continue to Review” | Case participants |
| Import from Microsoft 365 | Document Ingestion | “Import from SharePoint” | Only when enabled by your organisation |
| Configure stages | Case workspace | “Review Workflow Setup” → “Save Workflow” | Lead |
| Assign a document | Documents tab | “Assign Reviewer” | Lead only |
| Bulk final sign-off | Documents tab | “Sign Off Selected” (freezes!) | Final Approver / Lead |
| Delete documents | Documents tab | “Delete” | Lead only |
| Extend the deadline | Case | “Extend deadline” (reason mandatory, audit-trailed) | Lead only |
| Detection rules | Left nav | “Custom Rules” (Active rules run; Drafts never match) | Lead / Senior Reviewer |
| Deadline health | “Home” | “Statutory deadline health” — “On track” / “Urgent” / “Overdue” | All case roles |
| Live disclosure record | Case tabs | “Withholding Schedule” / “Audit Trail” | Any case role |
| Release | “Finalise & Close” | “Mark as released” — terminal, freezes everything | Lead |
| Close / reopen | “Finalise & Close” | “Close & archive” / “Reopen case” | Lead |
| Packages | “Finalise & Close” | “Requester Package” / “Internal Package” / “Ombudsman Package” | Lead: all three |