---
name: redaction
description: >-
  Mark a document for redaction before it is released or shared, under the standard the user names: personal identifiers, a Florida public-records or federal FOIA release, a federal or Florida court filing, HIPAA Safe Harbor de-identification, confidential business information, or a list the user gives. Writes a redaction code at each place of deletion, keeps a redaction log that never repeats a redacted value, and tells the user how to apply the redactions and sanitize the file. Use for any request to redact, black out, anonymize or remove names, social security numbers, dates of birth, account numbers or other sensitive information.
---

# Redaction

**This skill marks redactions. It never applies them, and it must tell the user so.** A mark is
only a replacement in a copy of the file. If the file is edited with tracked changes on, a marked
name stays inside the file as a tracked deletion that anyone can restore with Reject, and even
without tracked changes the same value can survive in a header, a comment, a property or a link.
Nothing is safe to release until the user has applied the redactions and sanitized the copy.

Answer in the vocabulary redaction tools use, whatever words the user chose. Text is **marked for
redaction**, **applying** redactions makes them permanent, **sanitizing** removes hidden data, the
text left in place is the **redaction code**, and the record of each one is the **redaction log**.

## Step 1: settle the standard, the level and the mark style

List the `standards/` folder beside this file and read every file in it. **Each file is one
standard, and the user may have edited them or added their own, so follow the files as they are
now and never what you remember of a standard.** A file's first heading is its name, and its "When
to use" section says which requests it serves.

Three things decide a redaction.

1. **The standard**, meaning which file applies.
2. **The level**, either "Only what must be withheld" or "Everything that may be withheld", which
   each file's "Levels" section defines and gives a default for.
3. **The mark style**, meaning what replaces the text. **Code** writes `[REDACTED: <code>]`,
   **Label** writes `[REDACTED]`, and **Bar** writes exactly `█████`. Never make a mark as long as
   what it replaces, because the length of a mark tells a reader the length of the name.

**When the message or the earlier conversation settles the standard, start at once.** It is
settled when the user names a standard or describes a request that one file's "When to use"
covers, so "before we answer the public records request" is the Florida file. A list of things to
remove, such as "redact Acme and everyone who works there", is `custom-list.md`. Take the level
and mark style the user stated, and otherwise each file's defaults, and say in the first line of
your reply which defaults you used.

**Otherwise ask once, and mark nothing until the user answers.** Ask only what is still open:

- the standard, offering each file except `custom-list.md` by its first heading, and saying that
  the user may instead type a list of specific things to redact;
- the level, offering "Only what must be withheld" and "Everything that may be withheld";
- the mark style, offering Code, Label and Bar.

Put the option the user's words point to first and say it is the suggested one. **Never redact on
a standard you assumed**, because the standards disagree: HIPAA removes an e-mail address that a
Florida release must produce. When the answer arrives, read the chosen standard again, then start
at Step 2.

## Step 2: find every instance

Read the whole document, never a sample. For each category the standard lists, look for every
form it takes:

- a name as a full name, first name or surname alone, initials, a possessive, inside an e-mail
  address, in a signature block, and in a defined term such as `("Licensee")`;
- a number with and without separators, broken across a line, in a table cell, and in words;
- the same value repeated in a heading, a caption, a table and a recital.

Check every candidate against the standard's "What not to redact". When a candidate needs a fact
the document does not show, do not mark it, and list it under **Needs your decision**. Count the
instances per category as you go, so you can check the marks against them at the end.

## Step 3: mark

**Work on a copy of the file, never the original.** If you can edit the copy, replace each span
with its mark. A span is the whole value, so "John A. Smith" is one mark rather than three.

- **Partial redaction and codes.** Where the standard keeps part of a value, replace only the
  removed part, in the shape its "Full or partial" section shows. Write the code its "Redaction
  code" section gives, and join several bases on one span with a comma.
- **Leave the paragraph intact.** Change only the span, and never retype the paragraph, because
  retyping loses formatting and invites a changed word nobody asked for.
- **Hyperlinks.** Mark a link's text, and name the link for removal, as its target stays.
- **If you cannot edit the file**, do not paste it back retyped. Give the log in Step 4, whose
  locations let the user mark each place in their own editor.

## Step 4: the closing reply

Open with one sentence naming the standard, the level, the mark style and the number of marks.
**Redaction log.** Then give a table with the number, the location as a section heading or a table
and row, the category, the redaction code, and full or partial. Add what the standard's "What the
log must state" requires, such as the statutory citation. **Never write a redacted value in the
reply or the log**, because a log is often released with the document and a value written there
undoes the redaction.

**Count check.** For each category, give the instances found against the marks written. Then,
under **Needs your decision**, list what you did not mark because it needs a fact or a judgment.

**Where this did not look.** Say which parts of the file you read. Then say that these must be
checked by hand unless you read and marked them: headers and footers, footnotes and endnotes, text
boxes and shapes, an index or table of contents, image alt text, link targets, document properties
such as Author and Title, comments, hidden text and embedded files. Name any comment that holds a
marked value, and never delete one; log any hidden text you found as "hidden text, not marked".

**How to finish.** Give these as numbered steps, in this order:

1. Keep the original untouched, and do the rest in the marked copy, saved with `_Redacted` added to
   its name.
2. If the marks are tracked changes, accept or reject every other tracked change that is not a
   redaction, then choose Review, then Accept, then Accept All Changes.
3. In Word for Windows: File, Info, Check for Issues, Inspect Document, and remove comments,
   revisions, document properties and personal information, hidden text and invisible content, but
   check headers and footers by hand, as it deletes them whole. Word for Mac has no Inspect
   Document, so: Review, Delete, Delete all Comments in Document; Tools, Protect Document, "Remove
   personal information from this file on save"; clear the Title and every field that leaves under
   File, Properties; and replace hidden text (Edit, Find, Advanced Find and Replace, Format, Font)
   with nothing. Word for the web cannot change properties, so use the desktop app.
4. Search the copy for one marked value to confirm it is gone. The inspector cannot find white text
   on a white background, so text you cannot see may still be there. Send the copy as a file, not a
   OneDrive or SharePoint link, as version history can keep marked versions.

## The law the standards cite

Quote the text bundled in the `reference/` folder beside this file rather than paraphrase it; the
publisher's version at each file header's address governs. Florida:
`fl-statutes-119-011-definitions-including-redact.md`,
`fl-statutes-119-07-inspection-and-redaction-duties.md`, `fl-statutes-119-071-general-exemptions.md`,
`fl-statutes-119-0715-trade-secrets.md`, `fl-statutes-119-0725-cybersecurity.md`,
`fl-statutes-331-22-airport-security-plans.md`, `fl-statutes-668-6076-email-addresses-are-public.md`
and `fla-rules-2-420-and-2-425-court-filings.md`. Federal: `usc-5-552-freedom-of-information-act.md`,
`frcp-5-2-privacy-protection-for-filings.md` and `45-cfr-164-514-hipaa-deidentification.md`.

## What this skill will not do

It does not decide an exemption the document cannot show, apply redactions or remove hidden data,
and it does not certify a document as safe to release, so a person must review the copy.

## Sources

- Florida Statutes Chapter 119, public records, including 119.07 and 119.071, the 2026 Florida
  Statutes: http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0100-0199/0119/0119.html
- 5 U.S.C. 552, the Freedom of Information Act, as amended through Pub. L. 114-185 (2016):
  https://www.law.cornell.edu/uscode/text/5/552
- Federal Rule of Civil Procedure 5.2, effective Dec. 1, 2007:
  https://www.law.cornell.edu/rules/frcp/rule_5.2
- 45 CFR 164.514, HIPAA de-identification, eCFR as amended through 2026-09-01:
  https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- Microsoft, Inspect document, which says Word for Mac has no document inspector:
  https://support.microsoft.com/en-us/office/inspect-document-b0088a7a-d482-4b87-b762-7c94c7c71e23
