CaseLeaf

Handbook / A copy per reader: the black-out levels

A copy per reader: the black-out levels

A black-out says a passage should go. A level says who it should go from.

With levels on the black-outs, one working document can produce a different copy for each audience. The copy a reader gets does not contain what they may not see. Blacking out explains what a black-out is and what making one permanent does; this page covers the levels on top of it.

Delivering a copy per role

Nothing is enforced when a file is read. Anything this application enforced would be enforced by nobody: the file goes to another reader and the restriction no longer applies. PDF's own permission bits are widely ignored, and password-protected files open in tools anybody can download; see Protection.

What this feature delivers instead is a different document per role. The reviewer gets a file that does not hold the material at all: it is real, checkable, and survives the file being forwarded. It also fails safely. If that copy leaks, what leaks is the restricted version.

The levels

Four levels exist to begin with: public, internal, confidential, and counsel only, lowest first. The order is what a level means: it hides a mark from anyone ranked below it. Change the list in the Settings window; see Settings.

A level is kept on the mark as its word, never as its position in your list. Storing the position would mean that inserting a level in the middle silently reclassified every mark in every document you own.

A level nobody recognises counts as the most restricted there is. A document marked up by somebody whose list differs from yours must not quietly become public because your list is shorter. The failure that matters here is releasing material, so the unknown case leans toward safety.

Legal ▸ Find What Has to Go…

The step before the levels, on a document full of personal data.

It proposes a black-out over every identifier it can find: names, dates, telephone numbers, e-mail addresses, places and postcodes, web addresses and long reference numbers, across the whole document or across the pages picked in the sidebar. The mechanical kinds are found by pattern matching; names are found by the system's own recognition, running on this machine. Nothing leaves the machine: the thing being protected is the thing you would otherwise be uploading.

It finds and proposes. It never removes. Each find becomes an ordinary black-out mark that you confirm or delete, carrying the kind it matched as its reason. A list of what was removed and why exists without anyone typing it, which is what a committee or a data protection officer asks to see. It will miss some identifiers and over-mark others; that is why the result is only a proposal.

One run is one undo step. The status line counts by kind, such as twenty-seven dates, fourteen names or three reference numbers, rather than one combined total.

It has two limits on what it can see. An identifier split across two runs of text is not found; a telephone number broken by a line break is a case this can happen to. A document with no text at all is a scan: the words are a picture, and there is nothing to search. It offers to recognise the pages first, then searches again.

Legal ▸ Level of the Black-Out…

Gives a level to the black-outs you have picked, or, with nothing picked, to every black-out in the document. Someone who has just blacked out eleven passages under one exemption can say so once.

A selection with no black-out in it gets no result: the command is offered only when what you picked is a black-out, so it cannot reach past a selected line to marks you never chose.

The sheet shows how many marks it will restrict. It offers your own list of levels plus any the document already carries that your list does not: a file from elsewhere keeps its own vocabulary offered beside yours.

Setting a level draws the mark's outline in a colour for that level, so the page shows at a glance what is restricted and how far. The box itself stays black, because it still means something is being removed. The change is one undo step. On a document with no black-out marks, the command says so and does nothing.

Legal ▸ Export for a Level…

The copy one audience may have. It asks what the recipient's level is, then where to put the file, and writes it.

The levels offered are only the ones the black-outs in this document actually carry, not every level you have ever defined: a level nothing is restricted at would produce the same copy as the one below it. If no black-out here carries a level at all, it refuses and tells you to give one a level first.

What the copy contains

  • Everything restricted above their level is really gone. The page is taken apart, and the drawing under those boxes is simply not written to the new file, text and vectors alike. A picture under a box is decoded, the covered pixels painted out, and the picture written back, so those pixels no longer exist at the picture's own resolution. Nothing is merely covered over.
  • Everything at or below their level is left as it was, with no black box over it. Those marks come off the copy before it is written, so they are neither carried out nor drawn. The passage is simply there, as it always was.
  • The copy is flattened. Every other mark is drawn into the page rather than carried beside it: highlights, notes, shapes, text boxes, watermarks and page numbers arrive as part of the paper, where nobody can pick one up and drag it off. They stop being annotations, so text attached to a mark, such as a comment, a reply, or the reason a passage was blacked out, is not in the copy at all. What is visible on the page is what goes. The same burn is described on making marks permanent.
  • Everything that is not a mark comes across: the files attached to the document, its bookmarks, its printed page numbers, its named destinations, its form, its own links, where it opens, and each page's own metadata.
  • The words come back as text. A page rebuilt to carry out a black-out is a picture at that moment, so the finished copy is read again, and every word except the removed ones returns as searchable text. What was under a box cannot come back; it was never shown to the recogniser.
  • The document you are working in is not changed. The marks taken off for this recipient are put back the instant the copy is written, because the next audience has to be served from the same file.

A line goes into the history of the document you exported from: which level, how many passages were removed, and the name of the file that went out. This lets you say later which version went to whom without keeping a copy of each. See History.

The copy is named after the document with the recipient's level added after it. When it is written, the status line says how many passages were removed and how many were left as they are, and the finished file is shown in the Finder.

When it refuses

  • The file on disk still needs a password, whatever is unlocked on screen. The copy would come out blank. Open it, give the password, save it unprotected, and try again.
  • A black-out could not be carried out in full. Nothing is written. A copy that looks redacted but still holds the material is exactly the failure this feature exists to prevent, so a refusal that left a file behind would still be that failure, only with a warning shown.

Availability

These three commands belong to an option. Without it they say so and do nothing. Everything else in the application is unaffected, and making marks permanent is included and always will be.

Watch: a short video for this page is still to come.


Blacking out · Making marks permanent · Protection · Sending a document for review · Contents