Get live legislative updates on your mobile devices

Download now

Back to blog
Legislative Advocacy
8
min read
15 Sep 2026

Public Records Requests: From Intake to Release

A request arrives, the agency interprets it, searches itssystems, reviews what it finds, applies exemptions, and releases the restbefore a statutory deadline. Most agencies have automated the arrival and therelease. The search and review in between are where the time and the exposuresit.

That shape is worth stating plainly because mostdescriptions of public records work stop at the administrative layer. Theydescribe logging a request, acknowledging it, assigning a number, and trackinga due date. All of that is real, and a records office that does it badly willfeel the difference immediately. But a records officer does not miss a deadlinebecause a ticket was misfiled. The deadline slips because searching acrossmail, shared drives, and a case system took eleven days, and the review thatfollowed took another six.

This guide covers the request end to end and the office thatruns it, because in practice those are one subject. The lifecycle ismeaningless without the routing, the staffing, and the department that has notreplied, since those are what actually determine whether a deadline is met.What the law permits an agency to withhold is a separate question, and a largeone, handled in withholdingand redaction.

Two notes on scope. This is written for the agency side, forthe custodians, public information officers, clerks, and counsel who receiverequests rather than file them. And it treats federal FOIA, state publicrecords statutes, and local ordinances as distinct regimes, because they differon deadlines, exemptions, and fees in ways that matter.

What a request actually obliges an agency to do

A public records request is a formal ask from a member ofthe public for records an agency holds. In most jurisdictions the requesterdoes not have to explain why they want the material, does not have to be aresident, and does not have to be a journalist or a party to anything. Theabsence of a stated purpose is a feature of these laws rather than anoversight, and it is worth internalizing early, because a great deal offriction in records offices comes from a quiet wish to know why.

The obligation that follows has four parts. Locate what isresponsive. Decide what the law allows you to withhold. Release the rest. Do allof it within a statutory period. A fifth part is implied rather than stated,and it is the one that causes the most trouble later: be able to demonstrateafterward what you did.

Notice what the obligation is not. It is not a duty tocreate a record that does not exist, to answer questions, to compilestatistics, or to explain the agency's reasoning on a policy. Requestsfrequently ask for those things, and the correct response is usually to sayplainly that no responsive record exists rather than to assemble something new.

The default across these statutes is disclosure. Exemptionsare exceptions to that default, they are construed narrowly, and the burden ofjustifying one sits with the agency rather than with the requester. Startingfrom disclosure and reasoning toward an exemption produces different resultsthan starting from caution and reasoning toward release, and the first is whatthe law contemplates. See what a publicrecords request is for the definitional groundwork, and the lifecyclestage by stage for the map this guide follows.

What counts as a record, and where records live

Content decides whether something is a record. Not format,not location, and not whether anyone intended it to be official. If itdocuments public business, it is generally subject to disclosure, whether it isan email, a spreadsheet, a text message, a chat thread, a voicemail, a calendarentry, or a photograph of a whiteboard taken on somebody's phone.

The definition is statutory and varies, so the specificsbelong to your jurisdiction. What does not vary is the direction of travel.Over the past two decades the definition has widened almost everywhere, and thesystems holding records have multiplied faster than the definition has.

The two areas agencies most often get wrong

Drafts. A common instinct is that a draft is not arecord until it is final. That instinct is usually wrong on the facts andsometimes right on the outcome, for a different reason. A draft is typically arecord. Whether it can be withheld is a separate question that runs through thedeliberative process exemption, which protects pre-decisional and deliberativematerial. Conflating the two produces a confident answer that will not survivean appeal.

Personal devices. Many jurisdictions hold that arecord about public business is disclosable regardless of the device it sitson. That creates a genuine practical problem rather than a legal ambiguity: theagency owes material it does not control and cannot search directly. Policy isthe only real lever, and it works best written before an incident rather thanafter. Textmessages, personal devices, and chat platforms covers the ground in detail,and what countsas a public record covers drafts.

Where records actually live

Every agency has an official answer to this and a realanswer. The official answer is the document management system. The real answerincludes mail, shared drives that grew around projects, collaboration and chattools, case management, permitting and licensing platforms, HR systems, the ITticket queue, whatever finance uses, physical files, and material inheritedfrom a system that was decommissioned but never emptied.

Writing that list down is the single highest-value hour arecords office can spend, and most have never spent it. An inventory namingevery system and a custodian for each converts the hardest recurring question,which is where to look, into a checklist. It also makes exclusions visible. Asystem deliberately left out of scope is a defensible decision. A system nobodyremembered is not, and eight months later the only difference between them iswhether somebody wrote it down.

Intake, interpretation, and splitting a request

Intake is largely a solved problem, and it is worth sayingso. A portal accepts the request, generates an acknowledgment, assigns anumber, starts a clock, and keeps correspondence in one thread. Agencies thatstill run requests out of a shared mailbox will gain more from fixing that thanfrom anything else in this guide.

Interpretation is where the real work starts, and it is onlypartly solved anywhere. A request written in plain language has to betranslated into search terms, custodians, and date ranges. The requester wrotewhat they wanted in the vocabulary of someone outside the organization. Nobodyinside uses those words, the department that holds the material calls itsomething else, and the system it lives in has a third name for it.

Three habits make interpretation reliable.

Restate the request before searching. Write down whatyou understand the request to cover, in the agency's own vocabulary, with thecustodians and date range you intend to use. This takes a few minutes and itcatches misreadings while they are still cheap to fix.

Go back to the requester when scope is genuinely unclear.Most requesters will narrow willingly if the alternative is explained, becausea narrower request usually reaches them faster. Contacting them is aclarification, not a negotiation, and it should not be used to discourage.

Split requests that cover unrelated bodies of records.A single submission asking for correspondence about a contract and theevaluation documents behind it is really two requests. They sit with differentdepartments, they move at different speeds, and combining them means the fasterhalf waits for the slower one. Splitting lets you deliver in parts, whichusually satisfies the requester earlier and reduces total elapsed time. Interpreting avague or overbroad request goes further on both.

One small thing worth doing at intake, because it pays foritself repeatedly: write an acknowledgment that does more than confirm arrival.Naming the request number, the statutory period, the person handling it, andwhat happens next turns a steady stream of status enquiries into a much smallerone. The text is written once and reused forever.

The statutory clock, tolling, and extensions

Every one of these statutes attaches a deadline, and theperiods vary widely between jurisdictions. Some run in business days, some incalendar days, some require an initial acknowledgment on a short clock and thesubstantive response on a longer one. Your number comes from your statute, andan agency operating under more than one regime needs more than one number.

It is also worth checking what your statute counts as aresponse. Some require only a determination within the period, meaning theagency states what it intends to release and on what basis, with productionfollowing on a reasonable schedule. Others require the records themselves to bein the requester's hands. That distinction decides whether a large request isworkable at all, and agencies working under a determination standard frequentlyhave more room than they use, usually because nobody has read the provisionclosely in years.

The harder question is not how long you have. It is whatstops the clock.

Most statutes contemplate some combination of extensions forvolume or complexity, tolling while awaiting clarification from the requester,and pauses pending fee payment. Those mechanisms exist because the draftersunderstood that some requests cannot be answered in ten days. Agencies underusethem, and they underuse them in a specific way: they rely on the mechanismwithout documenting it.

The consequence shows up in reporting rather than in theindividual request. A request that was extended properly, with the requesternotified and the basis recorded, is a request handled correctly. The samerequest with the same elapsed time and no record of the extension is a laterequest. On paper those are indistinguishable from each other, and paper iswhat an oversight body reads.

Rolling production is the other underused mechanism.Releasing in batches as material clears review gets records to the requestersooner, keeps the file visibly moving, and stops one slow department fromholding up everything else. It also tends to defuse the requests that wouldotherwise turn adversarial, because most disputes begin with silence ratherthan with a decision the requester disagreed with. A requester who has receivedthree batches and been told what remains rarely appeals; one who has heard nothingfor five weeks often does.

This is also where the most demoralizing part of the jobsits. The clock runs against the agency as a whole. It does not pause because adepartment has gone quiet. A records officer routinely carries a deadline forwork they cannot compel anyone to do, and the only real protection is adocumented escalation trail. Deadlines,clocks, tolling, and extensions covers the mechanics.

Search: the stage that consumes the time

If you measure one thing in your records operation, measurehow long requests spend in search relative to intake and correspondence. Inmost agencies the ratio is lopsided in a way that surprises the people runningit, and it is the number that tells you where to spend money.

Search is hard for reasons that have nothing to do witheffort. Records are spread across systems that were never designed to bequeried together. Each was bought for its own purpose, by a differentdepartment, in a different decade. In a larger agency each bureau operates itsown way, and the records office has no authority over any of it.

Work from custodians outward

The instinct is to start from systems: search the mail, thenthe drive, then the case system. The problem is that this only ever reaches thesystems you already remembered. Starting instead from who was involved, andasking what each of those people used, reaches the tools that never madeanyone's list. It also produces a better record of the search, because custodiansare what an adequacy analysis asks about.

Build the terms out before you run them

A single keyword taken from the request is almost neverenough. Agencies use acronyms, project code names, and internal shorthand thata member of the public has no way of knowing. A request about a sheltercontract may require the contractor's name, the contract number, the internalproject name, the department's abbreviation for it, and two or threemisspellings that appear in real correspondence. Building that cluster of termstakes ten minutes and is usually the difference between a search that finds thematerial and one that returns a handful of obvious documents.

Handle the material that keyword search cannot read

Scanned binders, photographs, PDFs with no text layer,audio, and video return nothing from a keyword search. Optical characterrecognition solves the first three where it can be applied. Where it cannot,the material has to be listed and reviewed by hand rather than passed over.

The point worth dwellingon: a search that cannot read a document reports exactly the same result as asearch across a document that does not exist. Both come back empty, and nothingin the empty result tells you which one you are looking at.

Treat threads as documents

An email chain is one conversation. Treated as fortyseparate messages it produces forty review decisions, most of them duplicative,and a release package that is painful to read. Threading is a small technicaldetail with a large effect on review time.

Record the search as you run it

The legal standard in most jurisdictions is whether thesearch was reasonably calculated to uncover responsive records. It is astandard about method, not about outcome, which means missing a document doesnot by itself make a search inadequate. But it also means the agency has to beable to describe its method: systems, custodians, terms, date ranges. Thatdescription is easy to write while searching and unpleasant to reconstruct ayear later from memory. Searching acrossagency systems and therecord nobody found go deeper.

Routing, ownership, and departments that do not answer

Most tracking failures are handoff failures. A request thattouches three departments and belongs to none of them will sit, not becauseanyone refused it, but because each assumed another was handling it.

Two rules prevent most of this. Every request gets one namedowner, not a shared mailbox and not a department. And a request touchingseveral departments gets separate tasks with separate due dates under thatsingle owner, so partial progress is visible rather than hidden behind anaggregate status.

Ownership needs a named backup as well, which sounds likebureaucratic detail until someone takes two weeks of leave in the middle of acomplex request. The backup does not need to do the work. They need to be theperson who notices the file has stopped.

Scoring at intake makes routing faster: subject, likelycustodians, and rough volume, decided in the first few minutes by whoever opensit. The alternative is a request drifting for three days while people work outwhose it is.

The department that will not respond is the hardest problemin this guide, and it is a political problem wearing an operational costume.Software does not solve it. What helps is escalating on a schedule rather thanon frustration, in writing, with each attempt recorded. A trail of three documentedrequests to a department that produced nothing changes the character of theconversation with leadership. It moves the failure from the records office,which had no authority, to the place where the authority actually sits.

What that escalation looks like in practice is unglamorousand effective. A first request with a specific date. A second, copied to thedepartment head, restating the deadline. A third to whoever holds the agency'slegal exposure, usually counsel, stating plainly that the response will be lateand why. Each step is written, each is dated, and none of them require therecords office to have authority it does not have. The escalation works becauseit makes the cost visible to somebody who can absorb it. Routing to theright custodian and when adepartment will not respond cover both.

Review, approval, and release

Review is where the search results become a release. Everydocument is read against the request to confirm it is responsive, then againstthe law to decide whether any of it can be withheld.

Those are two separate passes and running them as one is acommon source of both errors below. Responsiveness is a question about scopeand it is usually quick. Exemption is a question about law and it is slow.Sorting for responsiveness first, across everything, means the slow pass onlyruns over material that actually needs it, and it gives you an early andreasonably accurate estimate of how long the request will take. Doing both atonce on each document in turn produces a review that cannot be estimated untilit is finished.

Two failure modes dominate, and they are opposites.

The first is deciding from scratch every time. Twocaseworkers apply the same exemption differently, or the same caseworkerdecides differently in March than in September, because nothing wrote down theearlier reasoning. Inconsistency of this kind is a record-keeping failurebefore it is a judgment failure, and it is the most common quality problem inrecords offices of every size.

The second is over-withholding out of caution. Withholding awhole document because part of it is exempt is not permitted in mostjurisdictions. Segregability requires releasing what can be released, and aredacted page is very often the correct answer where instinct suggestedrefusing the document.

Approval deserves one structural note. Counsel or asupervising custodian signs off, and that sign-off frequently happens overemail. When it does, the approval trail lives outside the system holdingeverything else about the request. Months later, reconstructing who approvedwhat means searching somebody's mailbox. Keeping approval inside the case filecosts nothing at the time and saves a great deal later. What may be withheld,how to redact it, and how to prove the decision afterward are the subject of withholding andredaction.

Fees

Most statutes allow an agency to recover something, commonlythe direct cost of copying and in some jurisdictions staff time spent locatingand compiling records. Fewer allow recovery of time spent deciding what towithhold, on the reasoning that the agency's legal review is a cost ofcomplying with the law rather than a service to the requester.

Fee waivers or reductions for journalists, researchers, andpublic-interest requesters are common, and are sometimes mandatory rather thandiscretionary. Where discretion exists, applying it inconsistently is its ownrisk.

Where fees are substantial, most statutes contemplate anestimate before the work starts, and many allow a deposit. Both exist toprotect the requester from a surprise invoice as much as the agency from unpaidwork, and using them properly means the requester gets a real number earlyenough to narrow the request if they want to. A great many large requests shrinkat exactly this point, not because the agency pushed back but because therequester discovered which part they actually cared about.

There is a judgment call underneath all of this that isworth naming. Fee recovery on small requests frequently costs more toadminister than it collects once you count the invoicing, the chasing, and theoccasional dispute. Agencies that set a floor below which they simply do notcharge tend to spend less overall and generate fewer appeals. That is a policydecision rather than a legal one, and it should be made deliberately andapplied consistently rather than left to whoever is handling the file.

Two practical cautions. Charging more than the statuteallows is a frequent basis for appeal, and it is an unforced error, because theamounts are usually small relative to the cost of the dispute. And a feeestimate that arrives late has effectively consumed part of the responseperiod, since the clock in many jurisdictions does not pause until the estimateis actually sent. Feesfor public records covers what can and cannot be charged.

Retention schedules and what still exists

A retention schedule decides what is available to producebefore a request ever arrives, which makes it a records-request topic eventhough it is usually owned elsewhere in the organization.

The logic is short. If a record was destroyed properly underan approved schedule, there is nothing to produce, and saying so plainly is acomplete and defensible response. If it was destroyed outside the schedule, theagency has a problem considerably larger than the request in front of it,particularly if the destruction happened after the request arrived.

The interaction with litigation holds deserves attention,because it is where the two failure modes meet. A hold suspends destruction formaterial that would otherwise be eligible, and it usually arrives from counselrather than from the records office. If the two systems do not talk to eachother, an agency can destroy on schedule something a hold had already frozen,which is a considerably worse position than simply being late on a request.

Ownership is the other recurring problem. The schedule istypically written by a records manager or an archivist, applied by IT and byindividual departments, and relied on by the records office, which frequentlyowns none of it. Nobody has to change that arrangement for it to work, butsomebody has to know the schedule well enough to answer a request confidently,and it is usually cheapest for that person to sit in the records office.

Two things follow. Records staff need to know the schedulewell enough to answer confidently rather than vaguely, because a hesitantanswer about why a record no longer exists invites an appeal that a clear onedoes not. And any pending request needs to suspend routine destruction ofmaterial within its scope, which requires the records office to be able to tellthe rest of the organization that a hold is in place. Retention schedulesgoes further.

Delivery, duplicates, and closing the file

Delivery is handled unevenly across agencies. Small releasesgo out by email without difficulty. Large ones become awkward, and the awkwardnessproduces workarounds: a shared link with no expiry, a physical drive, a fileservice the agency does not control.

Duplicate requests are the quiet cost here. A requester whocannot see what an agency has already released has no way to avoid asking forit again. Neither does the next requester with the same interest. Agencies thatpublish frequently requested material, or that can see at intake that a requestduplicates a completed one, reduce their own volume without refusing anybodyanything.

Closing a request is not the end of its life. A closedrequest remains subject to appeal, oversight review, and litigation long afterthe file is shut, which is why the account of what was searched and whymaterial was withheld has to survive the closure rather than living in the headof whoever handled it.

This is the point where Govflois designed to help, and it is worth being specific about where. Connectorsreach into the systems an agency already uses, including Microsoft 365,SharePoint, and Purview for mail search, so material is pulled into the casewithout anyone exporting and re-uploading it by hand, and without anything inthe source system being changed. Redaction rules the agency has establishedpersist and can be reused, so a judgment made once carries forward instead ofbeing made again. Confidentiality labels already applied in an agency's ownsystems are respected, and material excluded on that basis is recorded asexcluded rather than silently omitted. Deadlines run against configurablestatuses with an approval gate on extensions. Completed requests are deliveredas packages with a link policy the agency sets, covering expiry, downloadlimits, and whether opening one requires verification. Video redaction isavailable, along with transcription and summarization of body-worn camerafootage. Govflo is built to produce a Vaughn index and a reproducible searchtrail that can be replayed for in camera review.

The limits belong in the same paragraph as the capabilities.Govflo is not a document management system and does not replace an agency'ssystem of record. It is not a legal research tool and does not advise onwhether an exemption applies. Federal FOIA, state public records law, and localordinances are configured as distinct regimes rather than flattened into oneworkflow, with New Mexico as the first implementation. Coverage of any givenagency's systems depends on what those systems are, which is a question tosettle during evaluation rather than after it.

Running the office

Everything above describes one request. A records program isthe same work repeated under load, and the constraints change when you look atit that way.

Decide in advance, not per request

The smallest offices survive on standing decisions. Routingrules agreed once. A fixed set of exemption positions for the categories thatrecur. Templates for the common request types. A two-person shop covers asurprising amount of ground when it stops treating every request as a freshproblem, and almost none when it does not. The same statutory obligations fallon a three-person town clerk as on a state agency, which is worth sayingbecause the tooling market has not always reflected it. Running a recordsoffice when one person wears four hats is written for exactly thatsituation.

High-volume requesters are an operational problem

Some requesters file constantly. Most statutes give anagency no grounds to refuse someone for asking often, and treating volume asbad faith tends to produce the litigation it was meant to avoid. Proactivepublication and duplicate detection do more than any policy on the subject. Handlinghigh-volume and serial requesters covers the approach.

Measure the middle, and report outcomes

Count requests received and closed, because oversight bodiesask. Then measure the things that actually tell you something: time in searchversus time in intake, time waiting on departments broken out by department,the proportion of requests appealed, and where withholdings concentrate.

The department-level number is the one that changesconversations. A records officer saying that responses are slow gets sympathy.A records officer showing that one department accounts for most of the elapsedtime across forty requests gets a meeting with someone who can fix it.

The two questions worth answering first

If you are not ready to change anything, two measurementswill still tell you where you stand. How long does a single request spend insearch and review, as opposed to intake and correspondence? And could youdemonstrate, for a request closed a year ago, which documents were examined andwhy particular material was withheld?

Those two answers locate the exposure, and they do itindependently of any vendor decision.

‍

Frequently asked questions

How long does an agency have to respond to a public records request?
Can an agency ask why someone wants the records?
What if the records do not exist?

See it running on your statute

Govflo runs public records requests and open meetings from intake through to release, configured to the law that governs each request. Tell us about your agency and we will set up a working session.

Talk to us
Back to blog