Correction workflow
Prepare evidence for editorial review.
Corrections must never publish automatically. Because no approved production intake destination, retention owner, or security boundary exists yet, this form prepares a local draft and transmits nothing.
Required moderation path
How a future submission must be handled
- Submission received
- Spam, security, and privacy review
- Source and provenance review
- Editor verification
- Expert or legal review when needed
- Accepted or rejected with reasons
- Accepted change recorded in the changelog
- Submitter notified when contact was voluntarily provided
Local preparation tool
Correction draft
Privacy and security gates
Controls required before live intake
- Collect only the minimum information; contact remains optional.
- Publish a retention and deletion schedule with a responsible owner.
- Validate and sanitize on the server, rate-limit requests, prevent CSRF, and use accessible privacy-conscious bot protection.
- Accept no attachments until malware scanning and file restrictions are implemented.
- Restrict unpublished records through least privilege and an audit log; never publish personal contact information.
- Keep policy corrections separate from lived-experience or accessibility-barrier reports.
Current behavior: no request is sent, no server record is created, no analytics event is emitted, and the draft disappears when the page is refreshed or closed.