BASALT · JOURNAL

Redacting workplace investigation files

2026-08-15 · workplace investigation redaction

Investigation files are written on the assumption they stay internal and are read later by people they were never written for: the subject, their lawyer, a tribunal, sometimes a regulator.

The witness problem

Anonymity is usually offered to witnesses, and it is usually harder to deliver than it sounds.

Removing a name does nothing if the account describes a conversation only two people witnessed, or refers to what someone saw from a desk only one person occupies. In a small team, accounts identify their authors by content.

This is the central difficulty in investigation redaction and no tool solves it. Someone who knows the team has to read the redacted version and ask whether they can work out who said what.

Where the account itself identifies, the options are to summarise rather than quote, to obtain consent, or to explain to the witness at the outset that anonymity cannot be guaranteed. Promising what cannot be delivered is worse than declining.

What else comes out

Personal data of people incidental to the matter. Medical information disclosed during the process. Unrelated allegations against other individuals which frequently surface during interviews. The investigator's private working notes, if they are not part of the formal record.

Where it hides

Interview notes as separate attachments inside the PDF.

Metadata naming the investigator and the internal file path, which sometimes names the subject.

Tracked changes and comments in the draft report, which can contain a frank earlier assessment that was revised. This is a genuinely damaging disclosure and it survives conversion from Word more often than people expect.

Email threads appended as appendices, carrying every recipient in the headers.

When it is disclosed

Assume it will be. Investigation material is routinely produced in subsequent claims, and a file written as though nobody will ever read it is exactly the file that gets read out.

Redact for the tribunal at the time you write it, keep the unredacted original, and record what was removed and why.

The check

Extract the text and search for witness names. Read the metadata. List attachments. Then hand it to someone who knows the team.

This is a description of common practice rather than legal advice. Obligations vary by jurisdiction and by the terms you are working under, and the authority that governs your work is the one to check with.

Frequently asked questions

How do I protect witnesses in an investigation report?

Removing names is rarely enough, because accounts identify their authors by content in a small team. Summarise rather than quote where the account itself identifies, obtain consent, or tell witnesses at the outset that anonymity cannot be guaranteed.

What is most often wrongly left in an investigation file?

Tracked changes and comments carrying an earlier, franker assessment, interview notes attached inside the PDF, metadata naming the investigator and file path, and email appendices carrying every recipient in the headers.

Will an investigation file be disclosed later?

Assume so. Investigation material is routinely produced in subsequent claims, so redact for that audience at the time of writing, keep the unredacted original, and record what was removed and why.

How do I check an investigation redaction is adequate?

Extract the text and search for witness names, read metadata, list attachments, and then ask someone who knows the team to read the redacted version and say whether they can identify who said what.

Doing it in Basalt

Basalt is a native macOS PDF toolkit built around redaction that removes content rather than covering it. After writing a file it re-opens its own output with an independent parser, searches for the material again, and refuses to save if anything is found. It also strips metadata, XMP, attachments, embedded scripts and hidden layers as part of the same operation, and a separate Inspector reports what any PDF still hides, including documents Basalt did not create. Everything runs on your Mac: the engine holds no network entitlement at all, which macOS enforces at the code-signature level. A one time $29 licence covers up to three Macs, free for the first 24 hours. basaltformac.com, or brew install --cask chipmunk1101/tap/basalt.

Redaction that proves itself

Basalt destroys the content you mark, then re-opens the file it wrote and proves the content is gone before it saves anything. Your documents never leave your Mac.

DOWNLOAD BASALT 2.3.0 BUY $29 FREE FOR 24 HOURS · MACOS 13+