Who may see which site records: the shared, the company's own and the personal
An owner's representative requests the daily reports after an incident. The folder also contains a sign-in sheet and a report with injury information. Forwarding the whole folder would answer more than the request and expose material nobody reviewed.

Set access and release responsibilities before a request arrives. Identify records the project routinely shares, internal company material and records containing personal information. These are working groups that can overlap, not absolute ownership rules. Check the request, recipient and actual contract, privacy or disclosure requirements through the authorized people before material is released.
Make access decisions traceable
- List the routine shared records. Identify the actual documents, recipients and terms behind regular distribution. Record who prepares and approves each release. A broadly named folder such as 'site reports' is too vague if it also holds restricted attachments or draft accounts.
- Identify internal and sensitive contents. Mark cost rates, internal discussions and personal-information records for the appropriate review. Federal workplace privacy guidance includes attendance and personnel information and addresses limited access. It also explains that applicable employee-information laws vary; have the responsible adviser assess this company's actual requirements.
- Assign authority and request routing. Name who can approve routine sharing and who receives an unusual request. Record its purpose, scope, recipient and timing. Route formal or legal requests promptly to the appropriate company advisers; a record's internal label does not decide whether it must be disclosed.
- Review and record the release. Check the actual contents and attachments. If a limited extract or redacted copy is approved, identify it and preserve the original. Record the authorization, recipient, date, files and any conditions. Avoid copying a new audience simply because it was included on an earlier unrelated email.
Build the access register around roles and named responsibilities, with a backup contact. Review it when the team, project phase or recipient changes. Make the route easy for a foreman to use: they should know whom to send a request to and what information to include. Do not make them improvise a privacy decision from the trailer doorway.
Common mistakes
- Forwarding a whole folder instead of checking its contents.
- Treating record categories as automatic legal disclosure rules.
- Redacting the only original or bypassing the request's authorized review route.
Checklist
Review a records request
- Requester, purpose, scope and timing recorded.
- Routine sharing terms checked.
- Internal and personal-information contents identified.
- Release or disclosure decision routed to authorized people.
- Approved set and unchanged originals retained.
Check your understanding
Does a shared daily-report folder make every attachment shareable?



