Publication Workflow for Protecting Sources and Yourself
Protect sources, reporters, newsrooms, people involved, and people who provided materials by checking originals, publication copies, review roles, records, and post-publication response.
When publishing a reported article, protecting only the source is not enough.
The reporter, newsroom, people involved, people who provided materials, and people who were at the scene also need protection.
Conversely, if the reporter's own workflow is weak, the source may be inferred from there. Sharing materials through a cloud account under a real name, adding too much follow-up detail on social media right after publication, publishing photos that reveal the reporting time, or publishing a PDF that still contains edit history. Small mistakes like these put both the source and the reporter at risk.
This article organizes a publication workflow for protecting sources and yourself at the same time.
Separate the people and information to protect
Before publication, first separate what needs to be protected.
Even when you say "source" in one word, multiple people may be involved: information providers, witnesses, people named in materials, people who were at the scene, and newsroom staff responsible for the article.
| Who to protect | Information likely to be seen |
|---|---|
| Source | Information content, contact time, distribution scope of materials |
| Reporter | Contact path, reporting location, posting time, device |
| Newsroom | Sharing history, editor names, post-publication response |
| People involved | Photos, quotations, names in materials, backgrounds |
| Information shown to readers | Article body, images, materials, supplementary explanations |
If the protection target is vague, the information to check also becomes vague.
Before publication, write down "who would be in trouble if they were inferred."
Separate originals from publication copies
For reporting materials, separate originals from publication versions.
Originals have meaning as evidence and reporting records. Publication materials, on the other hand, should not retain unnecessary metadata or specific clues.
| Stage | Purpose |
|---|---|
| Original storage | Preserve evidentiary value and reporting records |
| Review copy | Check metadata, text/content, and incidental visible details |
| Publication copy | Remove unnecessary information and release externally |
| Post-publication storage | Manage which version was released |
The basic rule is not to publish originals as they are.
However, for materials where legal evidentiary value matters, it is better not to decide on processing alone. Consult the newsroom, legal staff, lawyers, and specialists.
Do Not Check the Article Text and Materials Separately
Checking only the article text and assuming it is safe, or checking only the materials and assuming they are safe, is not enough.
Even if the article text blurs the date and time, an attached image may retain the exact capture time. Even if a department name is hidden in a material, the article text may reveal the department. These combinations occur.
| Combination | What happens |
|---|---|
| Article text + photo | Place and time fill each other in |
| Article text + PDF | Hidden department or material scope becomes visible |
| Material + publication time | Connects with the source's behavior |
| Quotation + job title | Narrows possible speakers |
| Image + social media follow-up | Scene or people involved are inferred |
Before publication, check the article text, images, materials, publication time, and social media follow-ups together.
Even if each item seems safer on its own, the combination may become dangerous.
Separate pre-publication review roles
For high-risk reporting, it is safer not to finish the check alone.
The person who wrote the article knows too much about the reporting process, so they may become less likely to notice clues. A third party may notice expressions that narrow the candidate pool.
| Role | What to check |
|---|---|
| Article text reviewer | Proper nouns, timeline, quotation granularity |
| Materials reviewer | Metadata, filenames, PDFs, images |
| Source protection reviewer | How few people the candidates narrow to |
| Legal and safety reviewer | Legal risk, evidentiary value, safety issues |
| Post-publication reviewer | Replies, corrections, inquiry handling |
Even in a small newsroom, check with these roles in mind.
Even if the same person takes multiple roles, separate the time and reread from a different perspective.
Define Revision Criteria
In a publication workflow, define not only the conditions for publication, but also the conditions for returning the article for more work.
If you publish while still unsure, you may be forced to correct or delete the article after publication. In high-risk reporting, do not publish items whose judgment is unresolved.
| Revision condition | Reason |
|---|---|
| Source candidates narrow to a small number | The person can be inferred from the article text alone |
| Material metadata has not been checked | Creator or place may remain |
| Post-publication response is undecided | Too much information may be released during controversy |
| Legal risk has not been checked | Evidentiary value or defamation judgment may be needed |
| Impact on people involved is unclear | People other than yourself may be pulled in |
Sending the article back for revision is not a process for stopping the story.
It is a process for lowering publication risk and returning the article to a state where the publication decision can be made again.
Record the publication decision
For high-risk articles, record what was checked before publication.
Who checked the article text, which materials were turned into publication copies, which information was withheld, and who is responsible for post-publication response. A record makes it possible to review the decision if a problem occurs after publication.
| What to record | Reason |
|---|---|
| Publication filename | Shows which version was released |
| Reviewer | Allows rechecking if something was missed |
| Withheld information | Allows explanation of source protection decisions |
| Unpublished materials | Helps judge whether additional publication is possible |
| Post-publication owner | Clarifies responsibility for replies and corrections |
However, this record itself contains source information.
Manage the storage location and access permissions.
Decide the post-publication response first
Post-publication handling is also part of the publication workflow.
After the article is out, who will answer inquiries? Will the source be contacted? Will there be social media follow-ups? If a correction is needed, who decides?
| Post-publication item | What to decide |
|---|---|
| Reader replies | Who answers and within what scope |
| Source contact | Necessity, path, timing |
| Correction handling | How to show differences and explanations |
| Additional materials | Scope that may be additionally published |
| Controversy response | Criteria for prioritizing safety checks over rebuttal |
If you decide in a hurry after publication, it becomes easier to release information emotionally.
Deciding the response policy before publication makes it easier to protect the source and the reporter.
Be able to explain the decision to the source
Before publication, also check whether you are able to explain the situation to the source.
What will be published, what will be withheld, what form the materials will take, and what reactions may occur after publication. This does not mean making the source decide everything, but information that affects the other person's safety must be handled carefully.
If the source proceeds without understanding post-publication risk, unexpected danger may occur after publication.
In high-risk reporting, safety checks on the source side are important as well as checks inside the newsroom.
If there is remaining unease that you cannot explain, do not rush the publication decision.
Summary
To protect sources and yourself at the same time, check not only the article text, but also materials, metadata, publication time, contact paths, and post-publication response.
First separate the people and information to protect, then separate originals from publication copies. Do not check the article text and materials separately; look at whether the source can be inferred from the combination.
For high-risk reporting, separate reviewer roles and decide reply and correction policies before publication.
Anonymity is not work done only just before pressing the publish button.
It is a workflow that continues through reporting, editing, publication, and post-publication response.
Related tools
SecureDrop
An external resource related to this article. Open it only when it fits your situation and threat model.
Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.
URL : https://securedrop.org/
GlobaLeaks
An external resource related to this article. Open it only when it fits your situation and threat model.
Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.
URL : https://globaleaks.org/
