Module 01 — The Lead

Disclosure leads: official information / privacy officers, coordinators, governance and legal leads accountable for the agency’s disclosure obligations · 90 minutes (60 minutes content, 30 minutes hands-on exercise) · prerequisite: Module 00 — Foundation (roles, the disclosure lifecycle, detections and decisions)

Under LGOIMA the request manager role is shown on screen as “LGOIMA Lead”. Under OIA the request manager role is shown on screen as “OIA Lead”.

(This module calls the role “the Lead”.)

In a hurry? Jump to the quick-reference card or the knowledge check — or print the all-roles reference.

Learning objectives

By the end of this module you will be able to:

  1. Create a request on “Log a new request” and explain which fields Veil assigns automatically.
  2. Upload documents on “Document Ingestion” and read the processing indicators correctly.
  3. Configure the case workflow on “Review Workflow Setup” and assign documents with “Assign Reviewer”.
  4. Use the bulk-actions bar safely, respecting its role gating.
  5. Formally extend a statutory deadline with an audit-trailed reason.
  6. Create and manage “Custom Rules”, and explain why they are detection rules, not redaction rules.
  7. Monitor case health from the dashboard, the workflow strip, the Schedule and Audit Trail tabs, and “Reports”.
  8. Release, close, reopen, or early-close a case — and explain why release is terminal.

1. The Lead’s place in the workflow

The Lead owns requests from start to finish: creating cases, assigning work, setting and extending deadlines, and configuring the workflow. The Lead can also do everything the reviewing roles can — review, make disclosure decisions, send work back, and give final sign-off — and is the only role that can delete a document or create a case. Visibility is always organisation-wide.

Permissions are enforced by the server, not the screen. Some buttons you cannot use are hidden (for example “Sign Off Selected”); others are visible but will be rejected by the server — the system re-checks your role on every action.

The case lifecycle progression row showing Intake → Processing → In review → Sign-off → Released
The case lifecycle row — the journey the Lead owns, from intake to released (shown on a council-branded demo instance)

2. Creating a request — “Log a new request”

On New Case (“Log a new request”), you enter the request and Veil does the rest.

The “Log a new request” form with the read-only “Assigned on creation” panel showing the reference and statutory deadline
“Log a new request” — the read-only “Assigned on creation” panel shows the reference and statutory deadline (shown on a council-branded demo instance)
Under LGOIMA the deadline is calculated per s 12 (20 working days). Under OIA the deadline is calculated per s 15 (20 working days).

3. Uploading documents — “Document Ingestion”

On “Document Ingestion” (the case’s upload screen):

Routing an upload to a department. If your visibility scope is organisation-wide and the case has departments, the upload panel offers an optional “Department” selector — “Optional — route these documents to a specific department, or leave as “No specific department” to keep them visible case-wide.” The default, “No specific department — visible case-wide”, never blocks an upload; choose a department to stamp the batch to it. (Department-scoped uploaders don’t see the selector — their uploads are stamped to their own department automatically.)

Sensitive (New Zealand-only) processing. The same panel carries the “Sensitive — process in New Zealand only (no AI)” checkbox — see Module 00 and the feature reference for what it does and its born-digital-only constraint.

The “Import from SharePoint” tab appears next to the dropzone and is enabled when your instance is connected to Microsoft 365. On the current release the connected tab shows “SharePoint import — coming soon” — in-app library browsing is on the roadmap — so download the files from SharePoint and upload them directly; they join the same “Processing Queue” and run the same pipeline.

The Document Ingestion dropzone with the format badges (PDF, DOCX, XLSX…) and the Processing Queue list
“Document Ingestion” — the dropzone with its format badges and the Processing Queue (shown on a council-branded demo instance)

Three format warnings worth repeating to your team: .PST email archives and .ZIP folders are not expanded — a ZIP is rejected at upload; export emails as EML or MSG, or unzip first, and upload the files individually. Standalone image files (PNG, JPG and similar) are rejected at upload with “Unsupported file type — supported: PDF, Word, Excel, PowerPoint, email (.eml/.msg), text.” — scanned material must arrive as a PDF, which is read through OCR as normal. Audio and video files are not screened — they may upload, but in a standard deployment Veil does not transcribe, detect, or redact them; never treat a media file as reviewed.

Note: An archive attached to an email (.zip and similar) is never processed silently — it becomes its own child document marked “Error”, so you can see it needs manual handling. Extract the archive and upload its files individually.

Reusing documents from a similar case

If a similar past case already holds documents that are in scope for this request, you can copy them in rather than gathering them again. This works from the case page, not at intake — the case must exist first, because the copies need somewhere to land.

  1. Open your case and select “Find Similar”.
  2. Find the case you want to reuse from, and select “Attach documents…” on its row.
  3. Tick the documents you want — you only see documents you are entitled to open — and select “Attach”.

What to hold onto:

The analysis that rides along with an attached document is imported, not re-run, and every imported detection still arrives pending — Module 02 covers what that means at the review desk. Full walkthrough: Find & reuse past work.

4. The automated pipeline, at a high level

Each uploaded document is processed automatically:

Every detection starts pending — Veil never decides for anyone; nothing is pre-redacted. People make every decision.

5. Configuring the workflow — “Review Workflow Setup”

The Lead configures who works each stage on “Review Workflow Setup”:

Under LGOIMA the Leads palette is labelled “LGOIMA Leads”. Under OIA the Leads palette is labelled “OIA Leads”.

This screen configures the workflow stages, not who works each document. To assign a document to a person, use “Assign Reviewer” on the case’s Documents tab (next section).

Requiring senior endorsement before final sign-off

For a case that warrants a formal second pair of senior eyes, the Details tab carries a “Senior endorsement” card with the toggle “Require senior endorsement before final sign-off”“When on, each document needs a senior reviewer’s formal endorsement after review before it can be signed off.” (Lead only.)

6. Assigning documents and the bulk-actions bar

On the case Documents tab, tick per-row checkboxes (or the “Select all documents” box) to reveal a bulk-action bar. Filter first with the “Search documents...” box if the list is long.

“Sign Off Selected” locks every selected document at once — the same lock as a single final approval, and undoing one means a per-document “Send back” from “Finalise & Close” and a reset attestation round. Confirm each one is correct first; a signed-off document’s redactions cannot be changed while it stays signed off.

Each bulk action authorises every selected document independently, so a selection straying into a department you cannot access is rejected as a whole — not silently trimmed. The same reject-whole applies on the assignment axis: if any selected document is assigned to another person, the whole selection is rejected — even for the Lead. Reassign it to yourself (or clear the assignment) first, then bulk-act.

7. Extending the statutory deadline

The statutory deadline is assigned automatically at intake, but the Lead can formally extend it when a request genuinely needs more time.

The Details page holds three more Lead-only controls worth knowing:

Correcting “Date received”

If the date was entered wrongly at intake, the Details page lets the Lead edit “Date received” and press “Save date received”. This re-derives the statutory deadline from the corrected date — the audit trail records “Changed date received and re-derived the statutory deadline” with the old and new values. There is no reason field, so use it only for what it is: fixing a data-entry error. A genuine need for more time is “Extend deadline”, which requires a reason.

Case notes

The Details tab has a “Notes” panel — “A single administrative note for this case. Editable even after the case is closed or released.” Write with “Add a note…” and press “Save notes” (Lead only; audited). It is deliberately the one case-detail field that stays editable after close/release — an annotation layer for context like “requester phoned to narrow scope”, never part of the frozen statutory record.

Departments on a case

The Details tab’s “Departments” panel lets the Lead add (“Add a department…”“Add department”) or remove (the ✕ on a chip) departments while the case is open. The standing rule shown on the panel: “A case must keep at least one department. A department can’t be removed while documents are scoped to it or reviewers are assigned to it.” — reassign or clear those first; removal is refused with a count of what still references it. Adds and removals are audited.

8. Custom detection rules — “Custom Rules”

“Custom Rules” teaches Veil agency-specific things to look for — “Agency-specific detection rules that run alongside the AI — keywords, patterns and entities mapped to withholding grounds.” The screen is shared between the Lead and the Senior Reviewer.

These are detection rules, not redaction rules — “Rules supplement the AI — they never override a reviewer.” A match becomes an ordinary detection for a person to accept or reject.

Rules named “Auto: …” were not typed in by hand: when a reviewer adds a manual detection and promotes it to a rule from the review screen, Veil creates a Draft keyword rule named “Auto:” plus the detected text (for example, a manual detection of “Priya Nair” becomes “Auto: Priya Nair”), with fuzzy matching and a description recording who suggested it. Like any Draft it never matches until someone reviews and activates it — treat the “Auto:” list as a suggestion inbox from your reviewers.

The Custom Rules screen — the rule list with Type, Withholding ground and Active/Draft toggles, the stat strip, and the “supplement the AI” note
“Custom Rules” — the rule list with Active/Draft toggles, the stat strip, and the “supplement the AI” note (shown on a council-branded demo instance)

9. Monitoring the caseload

The Veil dashboard (“Home”) showing the deadline-health panel and the personal queue
The dashboard — “Statutory deadline health” and the personal queue (shown on a council-branded demo instance)
Under LGOIMA the compliance report is “LGOIMA Compliance Summary”. Under OIA the compliance report is “OIA Compliance Summary”.
The Reports screen — the “Generate a report” cards (Compliance Summary, Withholding Schedule, Chain of Custody, Cost Recovery) and the reporting-period selector
“Reports” — the “Generate a report” cards and the reporting-period selector (shown on a council-branded demo instance)

10. Export packages — the Lead can produce all three

Package generation and download are gated by role tier; the Lead is the only role, alongside the Final Approver, that can produce all three:

Generating an external package (Requester or Ombudsman) requires the case to be fully attested and your agency name to be set — otherwise the export is blocked with an explanatory message. Veil fail-closes: an external release is blocked if the automated check finds a leak or cannot run.

The “Select Export Package” cards with the per-package “Includes” lists
The “Select Export Package” cards with their per-package “Includes” lists (shown on a council-branded demo instance)

11. The end of the case — release, close, reopen

The end of the case lives on “Finalise & Close”. The assigned Final Approver completes the “Final sign-off” panel (“Attest case complete”, choosing a “Disclosure outcome”: “Granted in full”, “Granted in part”, or “Refused”). Then the Lead takes over:

Release is irreversible. Be certain the package you have generated and checked is the one you intend to disclose before marking the case released.

The Finalise & Close screen with the three package cards (Requester / Internal / Ombudsman) and the “Generate Export Package” button
“Finalise & Close” — the three package cards and “Generate Export Package” (shown on a council-branded demo instance)

Hands-on exercise

Work on the demo instance (demo seed data; upload the sample files provided by your trainer — never real case material).

  1. Create a case. Open “New Case” and complete “Log a new request”: a short “Request summary”, a fictional “Requester name”, and two departments under “Department(s)”. Before pressing “Create Case”, note the auto-assigned “Reference” and “Statutory deadline”.
  2. Upload. On “Document Ingestion”, drag in the sample files. Watch “Processing Progress” and the “Processing Queue”. Re-upload one file deliberately and observe the amber “Duplicate” warning; remove the duplicate. Press “Continue to Review”.
  3. Configure the workflow. Open “Review Workflow Setup”. Drag one person from “Reviewers” onto “First-Pass Review” and a Final Approver from “Approvers” onto “Final Sign-off” (a Senior Reviewer can only be dropped on the review stages). Press “Save Workflow”.
  4. Assign a document. On the Documents tab, tick two documents and use “Assign Reviewer” to assign them to a demo reviewer.
  5. Extend the deadline. Press “Extend deadline”, note the “Maximum Extension Date”, set a “New Deadline”, and enter a “Reason for Extension”. Then open the “Audit Trail” tab and find your extension entry.
  6. Create a rule. On “Custom Rules”, press “New rule”, build a Keyword rule mapped to a withholding ground, and use “Save as Draft”. Confirm the stat strip counts it under “drafts — not yet running”.
  7. Check case health. Return to “Home” and locate your case in the “Statutory deadline health” panel.

Knowledge check

Quick-reference card

TaskWhereLabelGating
Create a requestNew Case“Log a new request”“Create Case”Lead only
Upload documentsCase upload screen“Document Ingestion”“Continue to Review”Case participants
Reuse documents from a similar caseCase page“Find Similar”“Attach documents…”“Attach”Case participants
Import from Microsoft 365Document Ingestion“Import from SharePoint”Only when enabled by your organisation
Configure stagesCase workspace“Review Workflow Setup”“Save Workflow”Lead
Assign a documentDocuments tab“Assign Reviewer”Lead only
Bulk final sign-offDocuments tab“Sign Off Selected” (locks every selected document!)Final Approver / Lead
Delete documentsDocuments tab“Delete”Lead only
Extend the deadlineCase“Extend deadline” (reason mandatory, audit-trailed)Lead only
Correct the date receivedCase Details page“Date received”“Save date received” (re-derives the deadline; audited; protects an extension)Lead only
Case notesCase Details page“Notes”“Save notes” (editable even after close/release)Lead only
Departments on the caseCase Details page“Add department” / ✕ chip (min one; removal blocked while referenced)Lead only
Require senior endorsementCase Details page“Require senior endorsement before final sign-off” (needs a second-pass stage; locks once used)Lead only
Route an upload to a departmentDocument Ingestion“Department”“No specific department — visible case-wide” or a departmentOrg-wide-scoped uploaders
Send back a signed-off document“Finalise & Close”“Send back” — returns to “In Review”, unlocked; resets the attestation roundSenior Reviewer / Final Approver / Lead
Detection rulesLeft nav“Custom Rules” (Active rules run; Drafts never match)Lead / Senior Reviewer
Deadline health“Home”“Statutory deadline health” — “On track” / “Urgent” / “Overdue”All case roles
Live disclosure recordCase tabs“Withholding Schedule” / “Audit Trail”Any case role
Release“Finalise & Close”“Mark as released” — terminal, freezes everythingLead
Close / reopen“Finalise & Close”“Close & archive” / “Reopen case”Lead
Packages“Finalise & Close”“Requester Package” / “Internal Package” / “Ombudsman Package”Lead: all three
← Module 00 — Foundation Your role’s path may skip ahead — see Start Here Module 02 — The Reviewer →