# template_redacted_report `template_redacted_report` is a public exemplar for redacted release reports, disclosure control, and source-protection review. It is designed for lawful, accountable release workflows in intelligence, security, legal, or public-records contexts without publishing sensitive operational content. Run via the template monorepo from the repository root with `uv run python scripts/pipeline/stage_01_test.py --project templates/template_redacted_report --project-only`, then generate the canonical audit artifacts with `uv run python scripts/pipeline/stage_02_analysis.py --project templates/template_redacted_report`. Copy `manuscript/config.yaml.example` to `manuscript/config.yaml` in forks and preserve template integrity. ## When to use this template Use this template when a report needs **formal redaction before release**: classification ceilings, source-control markings, redaction decisions, authority review, reviewer approvals, source-safe hash ledgers, residual-risk checks, mosaic-risk checks, and a public audit packet must be validated before any sanitized narrative is published. ## Publication and rendering **Redacted Report Template: Disclosure Control and Release Audit** · v0.1.0 · Daniel Ari Friedman Concept DOI: [10.5281/zenodo.21298890](https://doi.org/10.5281/zenodo.21298890) | Version DOI: [10.5281/zenodo.21298891](https://zenodo.org/records/21298891) | Repository: [docxology/template_redacted_report](https://github.com/docxology/template_redacted_report) Publishing surface — 20 platforms, 2 published: | Platform | Tier | Status | Reference | Credentials | | --- | --- | --- | --- | --- | | zenodo | first-class | ✅ published | [10.5281/zenodo.21298890](https://doi.org/10.5281/zenodo.21298890) | `ZENODO_API_TOKEN` | | github | first-class | ✅ published | [docxology/template_redacted_report](https://github.com/docxology/template_redacted_report) | `GITHUB_TOKEN` | | arxiv | first-class | ⚪ available | — | — | | pypi | first-class | ⚪ available | — | `PYPI_TOKEN`, `TESTPYPI_TOKEN` | | ipfs_pinata | first-class | ⚪ available | — | `PINATA_JWT` | | ipfs_web3storage | first-class | ⚪ available | — | `WEB3_STORAGE_TOKEN` | | software_heritage | first-class | ⚪ available | — | — | | github_pages | first-class | ⚪ available | [docxology/template_redacted_report](https://github.com/docxology/template_redacted_report) | `GITHUB_TOKEN` | | cloudflare_pages | first-class | ⚪ available | — | `CLOUDFLARE_API_TOKEN` | | netlify | first-class | ⚪ available | — | `NETLIFY_AUTH_TOKEN` | | huggingface_hub | first-class | ⚪ available | — | `HUGGINGFACE_TOKEN`, `HF_TOKEN` | | osf | first-class | ⚪ available | — | `OSF_TOKEN` | | amazon_kdp | documented | 🟡 planned | — | `AMAZON_KDP_EMAIL`, `AMAZON_KDP_PASSWORD` | | google_play_books | documented | 🟡 planned | — | `GOOGLE_PLAY_BOOKS_SERVICE_ACCOUNT_JSON` | | gumroad | documented | 🟡 planned | — | `GUMROAD_ACCESS_TOKEN` | | leanpub | documented | 🟡 planned | — | `LEANPUB_API_KEY` | | lulu | documented | 🟡 planned | — | `LULU_CLIENT_KEY`, `LULU_CLIENT_SECRET` | | draft2digital | documented | 🟡 planned | — | `DRAFT2DIGITAL_API_TOKEN` | | stripe | documented | 🟡 planned | — | `STRIPE_SECRET_KEY`, `STRIPE_PUBLISHABLE_KEY` | | ingramspark | documented | 🟡 planned | — | `INGRAMSPARK_CLIENT_ID`, `INGRAMSPARK_CLIENT_SECRET` | _Keywords: redaction, disclosure control, release audit, source protection._ _Status legend: ✅ published (durable identifier recorded in `config.yaml`) · 🔵 reserved (identifier reserved but not yet registered by final publication) · ⚪ available (adapter implemented and locally verifiable) · 🟡 planned. This block is generated — edit `manuscript/config.yaml`, then regenerate with `uv run python -m infrastructure.publishing.status_report --project --write`._ The canonical renderer is https://github.com/docxology/template with `--project templates/template_redacted_report`. Rendered reports are disposable; source-owned redaction ledgers and release-audit reports are the durable evidence. ## Configuration Primary configuration lives in `manuscript/config.yaml`; forkable defaults live in `manuscript/config.yaml.example`. Public example segments, redaction decisions, release-policy name, and invented review records live in `data/example_segments.json`; they contain invented fixture text only. `manuscript/config.yaml` declares a single normal Stage 02 analysis script, `scripts/01_generate_release_artifacts.py`. It loads the fixture through the typed `src/redacted_report/artifacts.py` contract, applies `intelligence_release_review` and `build_comprehensive_release_packet`, then writes two deterministic public projections: | Artifact | Public contents | | --- | --- | | `output/reports/redaction_audit.json` | Policy outcome, review gate, findings, aggregate metrics, and paragraph metadata; no narrative text | | `output/data/release_ledger.json` | Redaction bounds/reasons plus source/public SHA-256 values; no source spans | The full sanitized packet exists only in memory during analysis. The public projections deliberately omit segment text, reviewer rationales, and reviewer identities. Development PDF variants remain explicit opt-in proof artifacts and are not part of the normal Stage 02 order. `render.redaction_visual` declares the proofing surface: redaction styles `blackout`, `whiteout`, `grayout`, and `blur`; PDF backgrounds `white`, `gray`, `black`, and `blur`; and near-zero left/right PDF margins for the minimal report style. The blur background is a review mode that blurs non-redacted context while leaving redaction spans visibly treated by the selected style. Generate the full development proof matrix, including template steganography/provenance post-processing, with: ```bash uv run python projects/templates/template_redacted_report/scripts/generate_dev_variants.py ``` Kmyth TPM sidecar sealing is optional and disabled by default. To request `.ski` sidecars for each steganography PDF and source-safe hash manifest, pass `--with-kmyth` or `--kmyth-binary-dir infrastructure/steganography/kmyth/bin`; add `--require-kmyth` when missing tools or failed sealing should block generation. When requested, `variant_matrix.json` records tool paths, runtime status, and sidecar counts. ## Tests Run: ```bash uv run pytest projects/templates/template_redacted_report/tests --cov=projects/templates/template_redacted_report/src --cov-fail-under=90 ``` ## Outputs and validation The validator checks classification ceilings, source-control coverage, redaction bounds, residual sensitive markers, release authority, orphan redaction decisions, reviewer approvals, and mosaic-risk accumulation. It builds sanitized release packets in memory, paragraph-level audit tables, source-safe redaction ledgers, segment hash manifests, residual-risk reports, review-gate reports, and organization-specific classification taxonomy adapters, including an intelligence-style taxonomy for `TOP SECRET//SCI`-style markings in invented fixtures. The Stage 02 writer projects those results into deterministic, text-free JSON evidence; Stage 04 validation checks the rendered public report once generated. ## Publication and boundaries This exemplar is a release-safety and disclosure-control template. It must not be used to publish real classified material, operational targeting details, source identities, or surveillance methods. Replace fixtures with lawful, cleared, organization-approved content only. ## Fork guidance Use `scripts/audit/copy_exemplar.py` for clean forks. Keep high-side source files outside the public repository, commit only sanitized fixtures, configure your lawful marking taxonomy explicitly, require source-safe ledgers and review records, and require an explicit release authority field before publication.