How it works
Six visible stages. One signed bundle. Every decision on paper.
SART's pipeline is intentionally legible. Each stage names its inputs, what happens, what comes out, and who is responsible. There are no hidden steps and no unattributed decisions.
- Stage 01
Intake
Responsible: Case adminInputsRaw SAR letter, document export from housing systems, identity-of-requester documents.
What happensBundle assembled. Identity-of-requester verified. Scope of request clarified in writing with the requester before the statutory clock anchors.
OutputsVerified bundle, scope statement, intake checklist.
- Stage 02
Forensic discovery
Responsible: Agent 1 (system)InputsVerified bundle and the scope statement.
What happensResolves the data subject across the bundle: name variants, addresses, tenancy and reference numbers. Ambiguous matches are marked needs-review — never silently assumed.
OutputsSubject map with confidence per match. Review queue for ambiguous matches.
- Stage 03
Classify & recommend
Responsible: Agent 2 (system)InputsBundle plus subject map.
What happensWalks every passage. For each one, recommends release-or-redact against the versioned ruleset (TP-PII, NOT-REL, LPP, MGMT-NEG in MVP). Every recommendation cites the ruleId and the reason in plain English.
OutputsPer-passage recommendations with ruleId, reason, and confidence.
- Stage 04
Adversarial audit
Responsible: Agent 3 (system)InputsAgent 2's recommendations.
What happensA red-team agent challenges every classification. Disagreements are escalated to the reviewer's queue with both positions logged. Agreement is not silenced; it is recorded.
OutputsAudit verdicts (concur / dissent / escalate) for every passage.
- Stage 05
Review & sign-off
Responsible: Named reviewer (your DPO / SAR officer)InputsBundle, classification draft, audit verdicts.
What happensReviewer applies the statutory test. They accept, override, or escalate each recommendation. Overrides require a reason. Sign-off is name-attributed and timestamped.
OutputsFinal redaction plan, signed in the reviewer's name.
- Stage 06
Delivery & evidence pack
Responsible: Auditor / DPOInputsSigned redaction plan.
What happensBundle exported. Evidence ledger written: every passage decision with its ruleId, reasoning, audit verdict, reviewer name, and timestamp — hash-chained. Export is gated on integrity verification.
OutputsDefensible bundle for the requester. Evidence pack for the ICO if challenged.
What this isn't
SART doesn't redact.
SART produces recommendations and reasoning. It does not apply the statutory test, and it never auto-releases a bundle. The named reviewer at your housing association decides — and signs.
This separation is deliberate. It is what makes the audit trail defensible: a clear chain from system recommendation, through adversarial challenge, to a human decision attributable to a named officer at a named time.
Run a pilot on your next SAR.
Two-to-six week engagement, on-prem deployment, one signed bundle at the end.