Disclose runs a subject access or freedom of information request as a case, from collecting the records through reviewing and redacting them to delivering the result over a secure link. Setting it up is an administrator job you only do once, and most of the time goes on getting search ready rather than on Disclose itself. After that the people you nominate as case managers work their own cases in the web app, and you shouldn’t need to touch it again.
This article describes Foldr 11.1.
What you’ll need before you start
Four things need to be in place before a case will do anything useful.
A Disclose licence. Look under Governance in Foldr Settings. If Disclose isn’t listed there, it isn’t licensed on your server yet, so get in touch and we’ll arrange a trial or add it to your licence.
Search, running, with your shares indexed for content. Disclose finds records by searching, so a share that isn’t indexed is a share a case cannot look inside. Indexing names and metadata alone isn’t enough here, because the point of the exercise is finding someone’s name in the body of a document. Indexing a share for search covers the per-share side, and if the search service isn’t running at all yet, start with Setting up Foldr Search.
OCR and visual extract on those same shares. OCR reads the text out of scanned paper and photographs, of which a request turns up a surprising amount (letters, forms, incident notes, anything that arrived on paper). Visual extract records where on the page each word sits, for those scans and for ordinary PDFs and Office files alike, which is what the redaction step later works from. Without the pair of them, scanned documents are effectively invisible to a case. If the Content with OCR profile isn’t offered on your shares, both are still available to you by hand, and Indexing a share for search has the route.
A share to use as a staging area, which must allow public links. More on that below.
One optional extra: if you want Disclose to suggest redactions automatically, your Foldr needs its AI configured. The suggestions are a convenience and nothing is ever redacted without a person approving it, so you can run cases perfectly well without AI and mark the redactions by hand.
Turning it on
Go to Foldr Settings, then Governance, then Disclose. On the General page, under Activation, switch Enable Disclose on.
That’s the only switch that matters for availability. If you ever turn it off, existing cases and everything collected into them are kept; case managers just can’t create new ones.
Which public holidays apply to you?
Still on the General page, under Response deadlines, choose your Public holidays calendar (England and Wales, Scotland, or Northern Ireland).
This affects freedom of information requests, which are counted in working days and so need to skip weekends and bank holidays. Subject access requests are counted in calendar months to the corresponding date, so the calendar makes no difference to them, but it costs nothing to set it correctly now.
Who’s allowed to run a case?
Under Case managers, add the people or groups who may create and run disclosure cases.
Nobody can create a case until someone is added here, so this step isn’t optional. It’s worth keeping the list short: your data protection officer, whoever deputises for them, and not much else. Each case manager only ever sees the cases they created or were assigned to, so adding someone doesn’t hand them a view of everyone else’s work.
Getting search ready (the step people skip)
For every share you’d want a case to be able to search, open the share in Foldr Settings, go to Search, and set the Search profile to Content with OCR.
That one choice does three jobs: it indexes file contents rather than just names, it turns on OCR so scans and images become searchable, and it fills in the visual extract file types that produce the on-page positions.
If a share is on Custom (advanced) rather than one of the profiles, the individual settings live on the share’s Content extraction page instead, one item further down the same menu. Check that Index file contents and Enable OCR are both on, and that the Visual extract box lists the file types you care about (PDF, JPG, JPEG, PNG, TIFF, TIF and GIF are what the profile sets).
Then let the crawl finish before you rely on any of it. A first crawl of a large share takes a while, and until it’s done, the files it hasn’t reached yet aren’t findable. Indexing a share for search walks through all of this with screenshots, including how to run the crawl and how to check which files came back empty.
We’ll be honest about what happens if you skip this. A case doesn’t quietly pretend a share doesn’t exist: shares that can’t be searched are written into the case’s search record as out of scope, with the reason, and shares outside the case manager’s own access are counted without being named. That’s the right behaviour, and it’s also exactly the line you least want to be reading out to a regulator, so it’s worth spending the afternoon on indexing before a real request lands rather than after.
Mailbox collection, if you’re doing it
Cases can collect straight from Microsoft 365 and Google Workspace mailboxes. This is set up per mail system, on the Mailbox collection page.
Service account. Choose the account collections run through. Case managers never pick this, and a mail system with no account set isn’t offered on cases at all, which is a reasonable way to leave one switched off.
Mailboxes that may be collected. Add the people, groups or addresses whose mailboxes may ever be read. Group membership is worked out when a collection actually runs, so an allow-list built from groups keeps up with your directory on its own. There’s an Allow any mailbox switch for the situations where every mailbox really is in scope, but most people should leave it off and name the boundary explicitly.
This is the important division of labour in Disclose: you set the outer boundary of what could ever be read, and the case manager chooses within it for each case. Neither of you can quietly widen the other’s decision.
Mailbox to test. Put an address in and press Test before you rely on any of it. It’s much better to find out here that the service account can’t reach a mailbox than to find out halfway through a case.
The staging area
Every case files its collected mail, imported mailbox exports and redacted copies into a staging area, chosen when the case is created (or set later, as long as nothing has landed in it yet).
Any share can serve as one, with a single condition: it must allow public links, because the delivery link for the finished bundle comes from there. Shares that don’t allow them appear in the picker marked “can’t deliver from here” and can’t be selected. The staging share is automatically left out of that case’s own content searches, which saves a case from finding the material it collected ten minutes earlier and treating it as a fresh discovery.
Our suggestion is a dedicated share that only your case managers can see, rather than reusing something with a wider audience.
Taking requests in through a form (optional)
If you’d rather requests arrived through a web form than by email, build a Foldr Form for it and add the action Create a disclosure case in the form’s settings. The option appears once Disclose is licensed and you hold the permission to create cases.
Requests that come in this way arrive as unclaimed cases, and a case manager claims one to take it on. The clock and the case record start from the form submission.
Checking it works
In the web app, go to Shared By Me and open the Disclosures tab, then choose New disclosure. Pick the request type, fill in who (or what) it’s about, add the requester’s details, and choose your staging area.
From the case, run a content search and see what comes back. Look at the search record as well as the results: it tells you how many shares were searched and how many were skipped, and skipped shares with a reason attached are the fastest way to spot a share you forgot to index.
What happens after setup
Case managers work each case through its Case, Items and Decisions tabs: verifying (or waiving) the requester’s identity where the request type calls for it, collecting from shares, mailboxes and manual uploads, marking items relevant or exempt, redacting third-party details, and finally assembling a bundle and releasing it as a secure link that can be expired or revoked. Every one of those steps is written to the case’s decision log, which is the record you’d hand over if anyone asks how the request was handled.
For oversight, Foldr Settings, Governance, Disclose has a Cases page listing every case on the server with its status. It’s read only, deliberately: it’s there so someone can see that requests are being answered on time without being able to reach into the work itself.