How to Submit Audit Logs

You filed a records request and the agency answered. Here is how to get those files to us.

What to send

Anything the agency released in response to a Flock records request. The search logs are the most useful, but the surrounding records matter too — network sharing exports, event logs, and screenshots of configuration settings all tell you something the search logs don't. The audit logs page describes each record type.

If you only got part of what you asked for, send it anyway. Partial responses are still worth having, and a refusal is itself worth documenting.

Send files "as-is"

Send the files exactly as you received them. Do not open and re-save them, do not merge spreadsheets, do not delete columns you think are irrelevant, and do not rename the files.

We can only accept spreadsheet files, not PDFs. Open records law in many states requires government bodies to provide public records in their original electronic format—you may consider re-requesting the data.

Proof the records came from a records request

Every submission needs something showing the files were released by the agency. Three ways to do that, and the form asks you to pick one:

  • Attach the response — the response letter, the response email, a records-portal message, or a screenshot of any of those. PDF, EML, TXT, PNG, or JPG.
  • Link a MuckRock request — the public MuckRock page already shows which agency responded and what they released.
  • Email it separately — send it to humans@haveibeenflocked.com and mention the agency name so we can match it up.

Redact your own personal information first. We only need the part showing the agency released the records — not your home address, phone number, or anything else you put on the request form.

Already on MuckRock? Just send the link

If the records came back through MuckRock, you don't need to upload anything or fill in the rest of the form. Paste the request URL and an email address and we'll take it from there — the files are already public, and the MuckRock page itself shows where they came from.

What we store about you

Your email address and the IP address you submit from are stored alongside the files, with the agency name and the confirmations you tick. The email lets us follow up about the records. The rest is a record that someone asserted these files came lawfully from an agency and were not altered.

This is the only part of the site that keeps a raw IP address; everywhere else it is hashed. It is not published and not shared. The privacy policy covers it in full.

What happens next

A person reviews every submission by hand. Nothing you upload goes straight into the public database. We check the files parse, work out which agency's searches they cover, and reconcile them against records we already hold before loading anything.

That takes time, and we may email you with questions. Once the data is loaded it shows up on the relevant agency pages, and we'll credit you by the name you give us — or not at all, if you leave that blank.

Submit your records

Loading the submission form…