Skip to content

Freedom-of-Information Response Workflow

Records-request workflow — instantiates Transparency for Accountability

Turns a member of the public's right-to-know into a delivered record: a request pipeline with a statutory clock, exemption tests, and redaction before release.

A Freedom-of-Information Response Workflow is the pipeline that carries an outsider's records request from "I want to see this" to a delivered, lawfully-screened response. Its defining move is that disclosure is pull, not push: rather than deciding in advance what to publish, it gives any qualifying requester a right to ask, and binds the holder to answer within a deadline — searching, applying exemptions, redacting what is genuinely protected, and handing over the rest. It converts a general right-to-know into a specific, enforceable delivery, request by request, with a clock running.

Example

A journalist files a request with a city for "all emails and the current policy governing police use of body-worn cameras." The FOI response workflow takes over: the clerk logs the request and starts the statutory clock (say, ten business days to respond), routes it to the police department to search, and applies the exemption tests — active-investigation material and officers' personal data may be withheld or masked, the policy document itself may not. What comes back is the policy in full, a set of emails with the names of uninvolved third parties redacted, and a line-item note that three emails are withheld under a named investigative exemption. If the search will take longer, the workflow issues a dated extension rather than going silent. The requester need not have justified why they want it; the right to ask, and the duty to answer on time, is the mechanism.

How it works

  • Anyone may ask; the holder must answer. Standing to request is broad and the duty to respond is triggered by the request itself, not by the holder's choosing.
  • Run the clock. Statutory deadlines govern acknowledgement, response, and any extension, so delay is bounded and itself accountable.
  • Screen, don't refuse wholesale. Exemptions are applied line by line — release what is disclosable, withhold only what a specific rule protects, and say which rule.
  • Redact and release. Protected fragments are masked and the remainder delivered, so a single sensitive passage does not sink the whole record.

Tuning parameters

  • Standing and scope — who may request and which record classes are reachable; broad standing maximizes the right, narrow scope limits burden.
  • Statutory clock — the length of the response deadline and the grounds for extension; short clocks force responsiveness but strain capacity.
  • Exemption breadth — how wide the withholding categories are and how strictly construed; broad, loosely read exemptions quietly swallow the right.
  • Fee and burden controls — search fees and "unreasonable burden" thresholds; set high, they become a soft denial.
  • Appeal path — whether a refusal can be challenged to an independent reviewer, and how fast; without it, the holder is judge of its own withholding.

When it helps, and when it misleads

Its strength is that it puts disclosure on demand into the requester's hands rather than the holder's: it reaches records no one thought to publish, and its deadline turns "we'll get to it" into an enforceable duty. It is the workhorse of investigative accountability precisely because it does not depend on the holder volunteering anything.

Its failure modes are the ways a duty to answer gets hollowed out while looking honoured. Exemptions read expansively become an all-purpose withholding; "still searching" extensions stretch into de facto denial; fees and burden claims price the right out of reach; and a heavy request can be met with a compliant, unusable dump. The countervailing principle is that exemptions are meant to be narrow and specific — the presumption is disclosure, and each withholding must name the rule it rests on — which is only real if an independent appeal can test an over-broad refusal.[1]

How it implements the components

This mechanism fills the on-demand-access slice — the request pipeline and its lawful screening:

  • stakeholder_access_map — it defines who may request, which record classes they can reach, and how standing is handled.
  • timeliness_and_update_cadence — it runs on a statutory clock: acknowledgement, response deadline, and bounded extensions.
  • emergency_delayed_disclosure_rule — it applies the exemption and deferral tests that legitimately withhold or postpone part of a response.
  • privacy_security_and_confidentiality_boundary — it redacts exempt, personal, or security-sensitive material before releasing the rest.

It answers a specific request; it does not proactively publish or translate records for a general audience (that's Plain-Language Transparency Report) nor keep the standing ledger of what was withheld and why (that's Redaction and Withholding Ledger).

Notes

Push and pull disclosure are complements: a good proactive-publication regime shrinks the FOI queue by releasing routine records up front, leaving the workflow for the non-obvious requests that reveal the most. A holder facing a flood of requests should read it as a signal of what to publish proactively, not only a workload to manage.

References

[1] Freedom-of-information regimes (such as the U.S. Freedom of Information Act and its many national and sub-national counterparts) are built on a presumption of disclosure with enumerated exemptions — investigation, personal privacy, national security, and the like — that are meant to be construed narrowly and applied to specific material, not invoked to withhold whole records. The narrowness of exemptions, and an independent appeal to test them, are what keep the right from being read away.