Bristlenose · mockup · 13 Sep 2026

Redaction indicator — the decided design

There was no user-visible sign anywhere that a project was PII-redacted — verified 13 Sep 2026 across the SPA, the report, the export, the static renderer and the Mac. ProjectInfoResponse carried project_name, session_count, participant_count and nothing else.

Decided and built the same day. One line in the report header, stated only when true, with “redacted” linking to the docs — and deliberately nothing in the export surfaces, which have anonymisation and only anonymisation. This page is now the record of that, not a menu: the rejected placement is kept below with its reason.

Palette Theme
Artefact — real pixels, what ships Commentary — reasoning, not the product

Decided — a line in the report header

Settled 13 Sep 2026. The fact is stated in the report header and nowhere else. “redacted” links to the docs page, which carries the detail so the header does not have to. It rides on /info, one of the payloads baked into the offline export, so the same field serves the live report and the file a client opens.

redacted project
report header · redacted
Acme onboarding study
6 sessions, 5 participants, Personally Identifiable Information redacted
FindingsSessionsThemesCodebook

“I called [PHONE] twice and nobody picked up, so I emailed [EMAIL] instead.”

p3 · 00:14:22
same report, not redacted — the header says nothing
report header · not redacted
Acme onboarding study
6 sessions, 5 participants
FindingsSessionsThemesCodebook

“I called 020 7946 0912 twice and nobody picked up, so I emailed sam@acme.test instead.”

p3 · 00:14:22
Commentary

Silence, not a negative. A “Not redacted” line on every report is noise, and faintly alarming to a client who never asked the question. The header renders nothing when the flag is false — and nothing, too, when the field is absent entirely, so an older export embed degrades to silence rather than to a claim.

The terms stay technical on purpose. An earlier draft worried “redacted” was opaque — redacted of what? — and proposed plainer wording. Overruled, correctly: PII and redaction are industry-standard for researchers, and that was my uncertainty rather than theirs. The docs link carries anyone who does want the detail.

Prose, not a badge. The wording is a sentence, so it sits in the header’s metadata line beside the session and participant counts, where facts about the report already live — rather than becoming a .badge, which is the atom for tags.

Considered and rejected — anything in the export surfaces

An earlier draft of this mockup put the fact in the Export dialog too, distinguished from the Anonymise checkbox by shape. Rejected. Kept here as the reference copy, because the reason outlives the sketch.

Commentary · why not

The export surfaces have anonymisation, and only anonymisation. “Remove participant names from labels” is an export-time choice about speaker labels. Redaction is a pipeline-time fact about transcript text, decided runs ago and unchangeable there. Put them in one dialog and they read as one setting with a broken checkbox.

The draft tried to manage that collision — an inert stated panel beside an operable checkbox, so the shapes disambiguate before the words are read. The better answer is not to create it: keep redaction out of the export surfaces entirely. The existing hint already draws the line for anonymisation on its own terms — “Names spoken inside quotes are NOT removed” — which is exactly what redaction does do, and exactly why the two must not share a frame.

Tokens inlined verbatim from bristlenose/theme/tokens.css + colors/palette-*.css. Components reused: .badge (the house atom), the shipped export-dialog structure and its real the report header's existing metadata line. No new component: the wording is a sentence, so it joins the session and participant counts where facts about the report already live, rather than becoming a .badge — that atom is for tags. Decision and reasoning recorded in docs/design-redact-pii.md.