Reviewing, Verifying & Delivering
The human checkpoint - download the archive, check the redactions, verify, and release the response securely.
Fisar never sends a response on its own. Every request stops here and waits for a person.
The request is waiting for you
A finished request shows Redaction Completed with a Not Verified badge. Data collection is done; release is not.

Step by step
Open the request
From SAR Monitoring or the dashboard.
Retrieve the password
Reveal it under SAR Password. You do not need to have remembered it.
Download the archive
Click Download. You get a password-protected ZIP.
Open and inspect
Enter the password and review the files. Check that the requester's own information is intact and that other people's has been removed.
Check the manual review folder
Where present, open Requires manual review - these are the least certain items.
Verify the redaction
Click Verify Redaction and confirm you have reviewed the files and take ownership of the release.
Send
Confirm dispatch. The requester receives a secure download link.
Share the password separately
By phone or another channel - never in the same email.
What to look for
| Check | Why |
|---|---|
| Requester's own name is visible | They are entitled to their own data |
| Other individuals are redacted | Third-party data must be protected |
| Name variants handled | "Joseph Michael Bloggs" should be treated as "Joe Bloggs" |
| Spreadsheets and slides checked | Names hide in cells and speaker notes |
| Faces correctly blurred | Where media is attached |
Verification is a recorded action. When you tick the confirmation box you are taking professional ownership of what is about to be sent. Do not verify a request you have not opened.
Delivery
The requester receives an email confirming their files are packaged and ready. The link is valid for 30 days.
The password is never included in that email. Share it by phone or a separate channel - sending both together defeats the protection entirely.
If something is wrong
If a redaction is incorrect, do not verify. Re-run the request with adjusted keywords, or handle the affected files manually before release.